Malware

What is “Malware.AI.4007323923”?

Malware Removal

The Malware.AI.4007323923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4007323923 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4007323923?


File Info:

name: 921B34D5B92A2F32B4B2.mlw
path: /opt/CAPEv2/storage/binaries/592544ec12d310ed94322dd75c88db58bab109bc934bc2e782900eb7a959e61b
crc32: B40C7279
md5: 921b34d5b92a2f32b4b234cf7be3d480
sha1: b6e42ee71fcfca77f014ebb97590e3393e49a6ed
sha256: 592544ec12d310ed94322dd75c88db58bab109bc934bc2e782900eb7a959e61b
sha512: edee0e34e56c60ae89e00de556a1b3eaf6a0c98adb051514ef65702857ee34081bc5e89e88f37b10de12529967b7ab7c074b239160a1f2eb2d8727ba4468c985
ssdeep: 49152:KyjNsB+gAt3VS2oY3KjwPcQwpNlzPLC24I:KyjNsMfYBfQwpNlbLCy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEA524099147E27BFCED08A3445491D0C29C7FAA7B128DCEE97AD58A141F082F7B6D87
sha3_384: 207aa38ffeacb2e164c9cbc85e8be94238b1a3dc782f50fcb842b2ff6a85754652777f57ebd403212802e779da764768
ep_bytes: e848050000e988feffff3b0d58154300
timestamp: 2020-06-25 10:38:29

Version Info:

0: [No Data]

Malware.AI.4007323923 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.AntiVM.trEF
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48162209
FireEyeGeneric.mg.921b34d5b92a2f32
CAT-QuickHealW32.BrowserAssistant.B7
McAfeeArtemis!921B34D5B92A
CylanceUnsafe
SangforTrojan.Win32.Gozi.gen
K7AntiVirusTrojan ( 0058d9201 )
K7GWTrojan ( 0058d9201 )
Cybereasonmalicious.71fcfc
CyrenW32/BrowserAssist.A.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.HODY
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R03FC0GAV22
Paloaltogeneric.ml
KasperskyUDS:Trojan-Banker.Win32.Gozi.gen
BitDefenderTrojan.GenericKD.48162209
AvastWin32:Trojan-gen
BaiduArchive.Bomb
TrendMicroTROJ_GEN.R03FC0GAV22
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftTrojan.GenericKD.48162209 (B)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74179865.susgen
AviraTR/Crypt.Agent.azgkw
MAXmalware (ai score=86)
Antiy-AVLGeneric/Generic.APUnArc.1
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataWin32.Trojan.PSE.1OZG4QA
CynetMalicious (score: 100)
VBA32TScope.Trojan.Delf
ALYacTrojan.GenericKD.48162209
MalwarebytesMalware.AI.4007323923
APEXMalicious
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgRouogRsXR3EA)
IkarusTrojan.Agent
FortinetW32/Injector.EQUG!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4007323923?

Malware.AI.4007323923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment