Malware

Malware.AI.2436218180 (file analysis)

Malware Removal

The Malware.AI.2436218180 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2436218180 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mbfce24rgn65bx3g.io23zc.com
mbfce24rgn65bx3g.p0alj2.com

How to determine Malware.AI.2436218180?


File Info:

crc32: D947F64E
md5: fad9bfdc425989abe3f938074f894394
name: FAD9BFDC425989ABE3F938074F894394.mlw
sha1: 1491b3cfec359fa98dbea5d78fa1d6b1f9d0ea2c
sha256: 17ab2b19045fddfb7fa01ffb7305ad9f2c0bf419acf8c942930b3c0bf579c1ff
sha512: 1174698580744f3168f80e4f826ec7ac398cbb2532f7bd7234d52c18fffc9ae7e520a7483960533d9234379e1c3f8ff407e5e9d48bcd0b1d70d237bc0f1639ca
ssdeep: 6144:XUSUg0KrYSmTjcbBvZkbVc6CVI5GBmCt4W:kSUUrYxTjcbBhuq6CVDB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015 Adobe Systems Incorporated. All rights reserved.
InternalName: Adobe Download Manager
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Download Manager
ProductVersion: 2.0.0.135
FileDescription: Adobe Download Manager
Translation: 0x0409 0x04b0

Malware.AI.2436218180 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10307
MicroWorld-eScanGen:Variant.Ransom.Sage.110
FireEyeGeneric.mg.fad9bfdc425989ab
McAfeeArtemis!FAD9BFDC4259
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Ransom.Sage.110
K7GWTrojan ( 005062051 )
K7AntiVirusTrojan ( 005062051 )
BitDefenderThetaGen:NN.ZexaF.34590.nq1@aaCCGVki
CyrenW32/Trojan.IHQM-4342
SymantecRansom.Cry
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.SageCrypt.fz
AlibabaRansom:Win32/SageCrypt.57bc9f52
NANO-AntivirusTrojan.Win32.SageCrypt.eltgtr
TencentMalware.Win32.Gencirc.114af25c
Ad-AwareGen:Variant.Ransom.Sage.110
EmsisoftGen:Variant.Ransom.Sage.110 (B)
F-SecureHeuristic.HEUR/AGEN.1129228
ZillyaTrojan.SageCrypt.Win32.70
TrendMicroMal_Cerber-23
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminTrojan.SageCrypt.pe
AviraHEUR/AGEN.1129228
Antiy-AVLTrojan[Ransom]/Win32.SageCrypt
MicrosoftRansom:Win32/Milicry!rfn
ArcabitTrojan.Ransom.Sage.110
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.fz
GDataGen:Variant.Ransom.Sage.110
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.SageCrypt.C1798869
Acronissuspicious
VBA32Hoax.SageCrypt
ALYacTrojan.Ransom.Sage
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2436218180
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.EBVP
RisingRansom.Milicry!8.A2F2 (CLOUD)
YandexTrojan.SageCrypt!rnLxUzuNIz8
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Kryptik.FOPV!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
Cybereasonmalicious.c42598
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.SageCryp.HwoC7oYA

How to remove Malware.AI.2436218180?

Malware.AI.2436218180 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment