Malware

Malware.AI.4004020184 (file analysis)

Malware Removal

The Malware.AI.4004020184 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4004020184 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Malware.AI.4004020184?


File Info:

name: 02FBF5F9534DD2519844.mlw
path: /opt/CAPEv2/storage/binaries/90b46ec4ea0f59f22087bf55eff0bcf20cf7d0056b39f6b71e10ebf501f68f74
crc32: D2A77389
md5: 02fbf5f9534dd2519844ccaef7df07a3
sha1: 526c37e48197540e9897dfe3be20d449e468b554
sha256: 90b46ec4ea0f59f22087bf55eff0bcf20cf7d0056b39f6b71e10ebf501f68f74
sha512: 71e055796a3f1e311c00f71a562234a3f35fba8232c5ee21c3b9cb8d982f2f5f1b538d24f2ec62809fec8ae480b2c80182b450438e36d240765a1e23dc061f57
ssdeep: 3072:5oIwm+Z8NH8maHJ83bXDvbW42KybaF90Ty3YIyHmY4DeCPz2WdKXJG56ixGZ:Twm+Wr3b3W42daF90TF9HX497hYM56im
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T196F3CE0D7D3F02E9FA1342B154171ED22265F9FE6BDE221EBA1316D88568F483F41663
sha3_384: ce1047f10ebccaf2e1345e8a99a827f3e4e23ff3bbdb1b9d2d0882236c7e781c221756e99c0e3f76e0abced5aa55a1c2
ep_bytes: b8d7e7cceb68d88540004109ce680010
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.4004020184 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.02fbf5f9534dd251
ALYacGen:Variant.Razy.900994
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.9534dd
BitDefenderThetaGen:NN.ZexaF.34062.kuZ@aaoz!!o
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
KasperskyTrojan.Win32.Copak.kxut
BitDefenderGen:Variant.Razy.900994
NANO-AntivirusTrojan.Win32.Copak.iwvlzn
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce74b3
Ad-AwareGen:Variant.Razy.900994
SophosML/PE-A + Troj/Agent-BGOS
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Razy.900994 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.bfss
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.334DFCE
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGenericRXGJ-XZ!131A8A89288D
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4004020184
APEXMalicious
RisingTrojan.Injector!1.CD26 (CLASSIC)
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4004020184?

Malware.AI.4004020184 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment