Malware

Malware.AI.2814248192 malicious file

Malware Removal

The Malware.AI.2814248192 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2814248192 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.2814248192?


File Info:

name: C5C82D0C4A6615B4A939.mlw
path: /opt/CAPEv2/storage/binaries/e2f74a0db8d2eade7581f7e7927ef2a9c145afae7e171d003b4653ec3928dad5
crc32: 7C7C64CA
md5: c5c82d0c4a6615b4a9392d1ebae9bc1b
sha1: f2a83a13a86f05f6b71e383ef3f66c62ca7e7372
sha256: e2f74a0db8d2eade7581f7e7927ef2a9c145afae7e171d003b4653ec3928dad5
sha512: e12e116684b77b47d484d7ea9940fed9346d200b08d9324012e8a3c464b9a886af25be9bb140b2f171298737a2f2eb4ed8f1ca11e5163382e0e433f52f1e7632
ssdeep: 24576:tsuanQwC66czfZxDieB1Wp6fP25yZ8rzzyknMSJPCOPlkaPTnowmYOtTomp6k6EO:CuV6hbZM01WUHZ8iajTQomp6O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E8533B8E5305CBCC84652F1A5A3691EDC94EC53D8CA4FB8D4B552D3A6EB4BC052B30B
sha3_384: d7e4696af4006507bdf72d7df76b75ad8f83afaa6e1b811bc6323abf724e7e53b8630b33fd3dacfce033bc2cb1fd0870
ep_bytes: 6060c60424498d6424400f81a976ffff
timestamp: 2011-08-04 04:16:56

Version Info:

FileVersion: 1.0.0.0
FileDescription: www.x5xx.net
ProductName: 炫舞西西
ProductVersion: 1.0.0.0
CompanyName: www.x5xx.net
LegalCopyright: 请勿非法使用|否则后果自负 炫舞西西
Comments: 稳定|简单|西西无毒辅助|
Translation: 0x0804 0x04b0

Malware.AI.2814248192 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47510388
FireEyeGeneric.mg.c5c82d0c4a6615b4
McAfeeArtemis!C5C82D0C4A66
CylanceUnsafe
K7AntiVirusAdware ( 004b942f1 )
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.3a86f0
CyrenW32/SuspPack.BQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.CGWNHAS
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.47510388
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.47510388
EmsisoftTrojan.GenericKD.47510388 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47510388
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1107278
KingsoftWin32.Heur.KVMH015.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Packed/Win32.Vmpbad.C425017
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.XD0@aS3F9lob
ALYacTrojan.GenericKD.47510388
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.2814248192
TrendMicro-HouseCallTROJ_GEN.R03BH0CKP21
RisingTrojan.Generic@ML.98 (RDML:iHt3IfgSgsnsVUWeCaAdvw)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Malware.AI.2814248192?

Malware.AI.2814248192 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment