Malware

What is “Malware.AI.2510115063”?

Malware Removal

The Malware.AI.2510115063 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2510115063 virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2510115063?


File Info:

name: 1C3692AD37E9B92E7C19.mlw
path: /opt/CAPEv2/storage/binaries/7f9fc12409c1a9ce9ed14e565ce8455de83d1cbe5dae3793a945f60b980dee2e
crc32: 180DC85D
md5: 1c3692ad37e9b92e7c198df0080d1d8b
sha1: e96c6451a8e97c6b98b2a0178e84529678509f3a
sha256: 7f9fc12409c1a9ce9ed14e565ce8455de83d1cbe5dae3793a945f60b980dee2e
sha512: 9925a9e2aa1c32f4b87d3fffefcafe721fee4b170445080d30cc8b9ff73299d9765ba6ded97b025a0e49332f6d3a6c7a489241a4ce839862cdc2bcc5659cc324
ssdeep: 49152:GcHiSQDn0ZtptAAyXDXzLgn6FAyR5eB/vt/L1:TQD0ZtptxyXDXzLgn6FAyjel1/L1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC95693D2A43AD89F27D3C71E7145689B8C62F3F108A882B01687E94F5743E29FDA5D4
sha3_384: 48199f968ca9b852de1c42c45335528bcdd4673cc6d84300d0b80c64670932133cb8259105eca732d9100032848fc4d7
ep_bytes: 60be00f07f008dbe0020c0ff57eb0b90
timestamp: 2021-01-06 11:50:47

Version Info:

CompanyName: 由兮米IDE生成
FileDescription: 王国保卫战1
FileVersion: 0.0.0.0
InternalName: 王国保卫战1
LegalCopyright: 0
OriginalFilename: 王国保卫战1
ProductName: 王国保卫战1
ProductVersion: 豪华版
Translation: 0x0804 0x04b0

Malware.AI.2510115063 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lpZC
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Fragtor.14782
FireEyeGeneric.mg.1c3692ad37e9b92e
CAT-QuickHealTrojan.GenericRI.S30113117
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!1C3692AD37E9
MalwarebytesMalware.AI.2510115063
VIPREGen:Variant.Fragtor.14782
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0050718d1 )
BitDefenderGen:Variant.Fragtor.14782
K7GWAdware ( 0050718d1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36792.4nNfa0oaRLpH
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Dropperx-9646337-0
KasperskyTrojan.Win32.Chifrax.cma
ViRobotTrojan.Win.Z.Fragtor.1969920
RisingTrojan.Chifrax!8.309 (CLOUD)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Xarfich.teemc
DrWebTrojan.PWS.Wsgame.56773
ZillyaTrojan.Chifrax.Win32.5790
TrendMicroTROJ_GEN.R011C0WKA23
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Fragtor.14782 (B)
IkarusBackdoor.BlackMoon
GoogleDetected
AviraTR/Xarfich.teemc
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Fragtor.D39BE
ZoneAlarmTrojan.Win32.Chifrax.cma
GDataWin32.Trojan.PSE.1TYMTF4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Chifrax.C4623797
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Fragtor.14782
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R011C0WKA23
TencentMalware.Win32.Gencirc.119c49f0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.1a8e97
AvastWin32:TrojanX-gen [Trj]

How to remove Malware.AI.2510115063?

Malware.AI.2510115063 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment