Malware

What is “Malware.AI.41400253”?

Malware Removal

The Malware.AI.41400253 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.41400253 virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Malware.AI.41400253?


File Info:

name: 29840D36EFD66F64130E.mlw
path: /opt/CAPEv2/storage/binaries/2be407862aa013976c0c72e811fceb7d428eb735476df5ca2e6bc4b283224752
crc32: 5A41C2FD
md5: 29840d36efd66f64130efeaa4b0a022c
sha1: e948fcf7a82e5b990dd105caf8c8889c7ee7eada
sha256: 2be407862aa013976c0c72e811fceb7d428eb735476df5ca2e6bc4b283224752
sha512: f0b0e7673be14efd697c1a594a48d21fbdbd0469117670af1fbe250a983455ce0138e2442458d785d7f9bb25ccc2277407815c69ad609b0e9a0c50f1b37f3fe9
ssdeep: 49152:1w22FQH6EEGQhHAPCbP6GH1mZCfnNV9xGZdODUOnNlWOezopixmqaKoHl5m18sNc:4F0GI87HoZiNI6NA6ixDEsNG+VZe
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1693679DCADC4EED5E2011336D4AC7AA511A369EF660683CC20DC6657B6C3AC26B4D37C
sha3_384: abe77613a068320f2bf8c915b1336b092c77b652c692bc8cb2d9467af5b4c3d521a46f12afbba6c49969f62f37c8fbee
ep_bytes: ff250080db00b7470046450015db0100
timestamp: 2021-11-21 16:51:32

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: DababyAIO
FileVersion: 1.0.0.0
InternalName: DababyAIO.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: DababyAIO.exe
ProductName: DababyAIO
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.41400253 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.29840d36efd66f64
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!29840D36EFD6
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
AlibabaPacked:MSIL/VMProtect.4538fa76
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.6efd66
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
APEXMalicious
ClamAVWin.Trojan.Bladbindi-1
BitDefenderGen:Heur.MSIL.Bladabindi.1
AvastWin32:Malware-gen
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/VMProtBad-A
TrendMicroTROJ_GEN.R067C0RL221
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
GDataGen:Heur.MSIL.Bladabindi.1
AviraHEUR/AGEN.1144755
Antiy-AVLTrojan/Generic.ASMalwS.34D7C2F
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34062.@x0@aCoDQPi
MAXmalware (ai score=88)
MalwarebytesMalware.AI.41400253
TrendMicro-HouseCallTROJ_GEN.R067C0RL221
YandexRiskware.VMProtect!UlEmkUyUSD4
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Application
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.41400253?

Malware.AI.41400253 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment