Malware

Malware.AI.4127834313 (file analysis)

Malware Removal

The Malware.AI.4127834313 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4127834313 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Malware.AI.4127834313?


File Info:

name: AAFE44CF6D066086DD44.mlw
path: /opt/CAPEv2/storage/binaries/c8233131c7187152bcc3d4272cd2d1378247ced26b4f7587eecf256989f4bf75
crc32: 2F58AADC
md5: aafe44cf6d066086dd44c638c83ce22d
sha1: a80ee9920a8521f23e58a8d68cb4ddddb9b5811f
sha256: c8233131c7187152bcc3d4272cd2d1378247ced26b4f7587eecf256989f4bf75
sha512: 840f4018bb0d4300546745569158ea77b5e2de9c96292f0a0ef6b3674a2720bfac97c4bc2cf2e8d5bdfaa6178d1274b167b4ca6067f8bd192e4d0f500d42edcb
ssdeep: 12288:i7TRqGTk+EsP8ZUsE+4DGsGLb6y3R1nWpPG13RPHgguW77xOLuAWRWYj:i7TR1BE7UsEUfNfWpP2PHgU7xUuAWRW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123159D53A6D15476C0671A7C4D376BAADDA9BF142B2088C367F47E88AE363C134392C7
sha3_384: 1fa57348c8bf55c7622c671bdc1f9839ff7e351717db1f7bc7e8b011dcbb5ca8d624e75cce897828c4283a23933d8672
ep_bytes: 558bec83c4f0b88c044700e8f060f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.4127834313 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebWin32.Induc
MicroWorld-eScanTrojan.GenericKD.38043170
McAfeeBackDoor-AWQ.b!egh
CylanceUnsafe
SangforTrojan.Win32.Inject.gen
AlibabaTrojan:Win32/Inject.f22d20f1
Cybereasonmalicious.20a852
BitDefenderThetaGen:NN.ZelphiF.34294.5GW@aiCmvShl
CyrenW32/Induc.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.DXWINEI
TrendMicro-HouseCallTROJ_GEN.R002C0OKG21
KasperskyHEUR:Trojan.Win32.Inject.gen
BitDefenderTrojan.GenericKD.38043170
NANO-AntivirusVirus.Win32.Induc.dffkeg
AvastWin32:Induc-W
Ad-AwareTrojan.GenericKD.38043170
SophosMal/Generic-S
ZillyaBackdoor.Hupigon.Win32.176720
TrendMicroTROJ_GEN.R002C0OKG21
McAfee-GW-EditionBackDoor-AWQ.b!egh
FireEyeGeneric.mg.aafe44cf6d066086
EmsisoftTrojan.GenericKD.38043170 (B)
IkarusWin32.Induc
GDataWin32.Virus.Induct.A
JiangminBackdoor/Hupigon.cnaw
eGambitUnsafe.AI_Score_100%
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.150B17
GridinsoftRansom.Win32.Wacatac.sa
ViRobotBackdoor.Win32.Z.Induc.934400
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32Backdoor.Hupigon
ALYacTrojan.GenericKD.38043170
MalwarebytesMalware.AI.4127834313
APEXMalicious
YandexBackdoor.Hupigon!j6VhGx44qzU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BDoor.AWQ!tr.bdr
AVGWin32:Induc-W
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4127834313?

Malware.AI.4127834313 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment