Malware

Malware.AI.4001173692 information

Malware Removal

The Malware.AI.4001173692 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4001173692 virus can do?

  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4001173692?


File Info:

name: 60874ADC6DCC0F554809.mlw
path: /opt/CAPEv2/storage/binaries/db53ecdc7c6017248dc6bb347519b810da5db8c7e2ffaa6fdfd6e8f4c2b3a866
crc32: D47E9B52
md5: 60874adc6dcc0f554809f8edb648ebfb
sha1: 0ee5c426388ef5a92015e710ee2e1d564f466a21
sha256: db53ecdc7c6017248dc6bb347519b810da5db8c7e2ffaa6fdfd6e8f4c2b3a866
sha512: 06bf8b4a5ffe3a8d760c1ad62e274480f430e96bfdea41e13f759f6536c0445007973674d688cfb6e67169d0595a807f4511c1ba4df65d323569813918274cee
ssdeep: 12288:GCOT1WlZ1YYAkWnkgPzIQyaXYfl/PH0XxpgdTpCPAMctJDdFFga/76VlGc4kZr:GCORWlZcF1yaXUzdT6AM+r2az6/Gc4s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0158D1273D2C072FFAB92738F6AF20596BC79250123A62F13981D79B970172576E723
sha3_384: 66a7431f30a236e8de0110659c817e6bd09c10434c6a31a580a61f426439764545d8e5b77f2de2e1c89fe21ed65270f3
ep_bytes: e8c5d00000e97ffeffffcccccccccccc
timestamp: 2022-03-01 08:05:18

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.4001173692 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.60874adc6dcc0f55
SkyhighBehavesLike.Win32.Ransomware.ch
MalwarebytesMalware.AI.4001173692
SangforTrojan.Win32.Agent.V0l5
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_70% (D)
APEXMalicious
ClamAVWin.Dropper.Autoit-6646809-0
AlibabaTrojanDropper:Win32/Generic.ca9ce40b
RisingTrojan.Obfus/Autoit!1.D77B (CLASSIC)
SophosGeneric Reputation PUA (PUA)
GoogleDetected
VaristW32/ABRisk.LPZD-3942
Antiy-AVLGrayWare/Autoit.BinToStr.a
Kingsoftmalware.kb.a.989
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32TrojanDropper.Autoit
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06DD23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.6388ef
AvastWin32:Malware-gen

How to remove Malware.AI.4001173692?

Malware.AI.4001173692 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment