Malware

What is “Malware.AI.2204503664”?

Malware Removal

The Malware.AI.2204503664 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2204503664 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
asonumls.azkazdzoxomj.net
ipecho.net
qcovufy.azkazdzoxomj.net
yturyfixun.azkazdzoxomj.net
oqigawon.azkazdzoxomj.net
osoqmfas.azkazdzoxomj.net
oliditaze.azkazdzoxomj.net
ilyl.azkazdzoxomj.net
ujot.azkazdzoxomj.net
wtizusul.azkazdzoxomj.net
ykyqrjan.azkazdzoxomj.net
twopax.azkazdzoxomj.net
dcublnuwi.azkazdzoxomj.net
fgiquketoni.azkazdzoxomj.net
udajyj.azkazdzoxomj.net
obkpypi.azkazdzoxomj.net
osysdw.azkazdzoxomj.net
yvik.azkazdzoxomj.net
avyzabav.azkazdzoxomj.net

How to determine Malware.AI.2204503664?


File Info:

crc32: DD45078F
md5: be4ec3f7650342883ad42cb063dcf062
name: BE4EC3F7650342883AD42CB063DCF062.mlw
sha1: e00ea6a27e9ded17946e2bf114fd7b0e58b0cda8
sha256: 98282d5e812211c7a5ab96ef228e5551f7a4c93e57816913361c99aca5a2b34a
sha512: 051d72f1ab10b072e38fa75343afe2335f4e930fe3cb8f591edcc2907809ba824c2830c2d505c3485a592fb2d312b4eeacc50b018285c49d37bc94db23616f83
ssdeep: 12288:5ivs1lN9ZsPrqZ4/rVfZrx+v24TnWIRM:Y0LN903/BZl+v03
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2013 Steganos Software GmbH
InternalName: TraceDestructor.exe
FileVersion: 17.0.2.11443
CompanyName: S teganos Software GmbH
LegalTrademarks: Steganos Safe 17 is a trademark of Steganos Software GmbH
Comments: Steganos Safe 17
ProductName: Steganos Safe 17
ProductVersion: 17.0.2.11443
FileDescription: Steganos TraceDestructor
OriginalFilename: TraceDestructor.exe
Translation: 0x0409 0x04e4

Malware.AI.2204503664 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5077
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacTrojan.Ransom.Crypto.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1308960
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 005224381 )
Cybereasonmalicious.765034
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/S-4770894f!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.EHIP
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-9783079-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Crypto.1
NANO-AntivirusTrojan.Win32.Encoder.evddvx
MicroWorld-eScanTrojan.Ransom.Crypto.1
TencentMalware.Win32.Gencirc.10b58632
Ad-AwareTrojan.Ransom.Crypto.1
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34722.Jq0@aGTgUIli
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hh
FireEyeGeneric.mg.be4ec3f765034288
EmsisoftTrojan.Ransom.Crypto.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.bqtda
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.22B531A
MicrosoftRansom:Win32/Teerac.I
ArcabitTrojan.Ransom.Crypto.1
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Crypto.1
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
McAfeeRansomware-GCQ!BE4EC3F76503
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Ranscrape
MalwarebytesMalware.AI.2204503664
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingTrojan.Kryptik!1.AE9C (CLASSIC)
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2204503664?

Malware.AI.2204503664 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment