Malware

Malware.AI.4104434450 (file analysis)

Malware Removal

The Malware.AI.4104434450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4104434450 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4104434450?


File Info:

name: 27ED436B45A702E50AE3.mlw
path: /opt/CAPEv2/storage/binaries/28a3b35b8c2467a370ed45c7f342fcc1562a9fed38cc0d9ec3477c77e7d2e169
crc32: 9C888BE2
md5: 27ed436b45a702e50ae306921f494281
sha1: e3e8a0dfb40adad5d2548ae66c5114839565cf29
sha256: 28a3b35b8c2467a370ed45c7f342fcc1562a9fed38cc0d9ec3477c77e7d2e169
sha512: 2be55c717a209e85a0208065610c938ae0bf4d86bf5b95a6bb3117579ee31aa56eab35984d91dad7f0f5ff80a59e30af1bd0e605378489cc309575953b209a5f
ssdeep: 98304:g8KW/Xr21Lq5z180grtwO55TxSgyg1mWcRAzfbOS9ut2tAnOI9sq56:SQXr21G4roEcRArvuQ2OEsl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173163342E5B30A7FFC2B9A380F806A907B3FEE155479AC64258F9E9D4D45BF0A305349
sha3_384: 5116db8bced2b90201b3c4581def6801dfe7abdd1e748c01ed2a4b3615363501485809146bffec3b209aeb535e6911ca
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-03-24 18:31:24

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: HTML To RTF Converter Setup
FileVersion:
LegalCopyright:
ProductName: HTML To RTF Converter
ProductVersion:
Translation: 0x0000 0x04b0

Malware.AI.4104434450 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.BadFile.rc
McAfeeArtemis!27ED436B45A7
Cylanceunsafe
SangforTrojan.Win32.Agent.Vd1o
K7AntiVirusTrojan ( 005722f11 )
K7GWTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.awtgh
AvastOther:Malware-gen [Trj]
F-SecureHeuristic.HEUR/AGEN.1373347
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/ABRisk.PWIM-2906
AviraHEUR/AGEN.1373347
KingsoftWin32.Trojan.Ekstak.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.awtgh
GDataWin32.Backdoor.Bodelph.QE0FE2
GoogleDetected
MalwarebytesMalware.AI.4104434450
TrendMicro-HouseCallTROJ_GEN.R002H0CCO24
IkarusTrojan.Win32.Crypt
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4104434450?

Malware.AI.4104434450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment