Malware

Malware.AI.2232989465 (file analysis)

Malware Removal

The Malware.AI.2232989465 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2232989465 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.2232989465?


File Info:

name: AD6B006EB8CE937675EC.mlw
path: /opt/CAPEv2/storage/binaries/de9d1a19a37d317e033fc7a7a9be2ce7128dfa97b6a25eb30f77d3b0ab2c03b1
crc32: 4AB1DAB4
md5: ad6b006eb8ce937675ec48c7ed8992b6
sha1: 1e8008823beddb30195103c3b52ce1b42296a1c6
sha256: de9d1a19a37d317e033fc7a7a9be2ce7128dfa97b6a25eb30f77d3b0ab2c03b1
sha512: 95405972d80f9f449a5fc966dd1d237ca1153970503d2c66fbf53a6f1785ad55668a6406790c6fac023eb9f4f4107475f83336270dd84a5c0be9bf8ed938fe82
ssdeep: 49152:HdVtcbjWX9/Eq6CHl6TZfbcWdleBDyfQI7AGqOTW9:1cXWX9/EPq/WmBx3POTe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199C5AF12B741C0B2C645063095A7F3769638BA035F2996CFB3CCDF6D2F712D0AB6A15A
sha3_384: fceaf4931b159552805dd23ec05e66e3028eda8a38e2f4098847324adf6428f9fb2f0303a2213ad3605cdd8d853f25d3
ep_bytes: 558bec6aff68208463006850614b0064
timestamp: 2021-11-18 11:02:01

Version Info:

FileVersion: 1.0.0.0
FileDescription: BOX宏
ProductName: BOX宏
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: BOX宏
Translation: 0x0804 0x04b0

Malware.AI.2232989465 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lKW0
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31221043
FireEyeGeneric.mg.ad6b006eb8ce9376
CAT-QuickHealTrojan.Agent
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.23bedd
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.FlyStudio.gen
BitDefenderTrojan.Generic.31221043
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.31221043
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftTrojan.Generic.31221043 (B)
GDataWin32.Trojan.PSE.12FI8JT
Antiy-AVLTrojan/Generic.ASCommon.FA
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
Acronissuspicious
McAfeeArtemis!AD6B006EB8CE
MAXmalware (ai score=80)
VBA32BScope.Trojan.Download
MalwarebytesMalware.AI.2232989465
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazp3dkK9LbSldEwmcXFdpBAp)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34294.Cs0@aOvDIXdb
AVGWin32:Malware-gen
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.2232989465?

Malware.AI.2232989465 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment