Malware

What is “Malware.AI.4163068122”?

Malware Removal

The Malware.AI.4163068122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4163068122 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Harvests cookies for information gathering

How to determine Malware.AI.4163068122?


File Info:

name: 1364BD81198ADDAA901F.mlw
path: /opt/CAPEv2/storage/binaries/291c5cca8abe1ee2f046128e1758877d18facc424a6ec39ca1e732f1f455825c
crc32: 25368CEC
md5: 1364bd81198addaa901f1a246ed2eec8
sha1: 6153cb807ca147f7d9d1b55dccb7592773d7a1a7
sha256: 291c5cca8abe1ee2f046128e1758877d18facc424a6ec39ca1e732f1f455825c
sha512: 001d74798b224ca7ec7836cbb2be2d6047bf5ae4fbe224f5679de2f4451f01015a5f810d965ca91cf26a3538039641a47a26d8166e94e00d89b32aacf691ef66
ssdeep: 1536:inB7Nt19em2I4w7T5WomTyjte5YhpsP4NlJBkU4FFhJ5:qBRt92ZwhjwyReXPkk5d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103440E63B16B23B5E9D7F7BF54B6A197C66FA743324F30FB6A142D0181838406C5E1A2
sha3_384: b9205be3046b61719c23156e3d9beb067c71a7abcbef4021901eb99125cfdd983b0b9de512d51cc3ac3ed8caff068b2b
ep_bytes: e8ae030000e935fdffff558bec81ec28
timestamp: 2010-01-24 00:55:30

Version Info:

0: [No Data]

Malware.AI.4163068122 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Generic.13150063
FireEyeGeneric.mg.1364bd81198addaa
ALYacTrojan.Generic.13150063
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderTrojan.Generic.13150063
ZillyaTrojan.GenericKD.Win32.466
McAfee-GW-EditionBehavesLike.Win32.Injector.dm
EmsisoftTrojan.Generic.13150063 (B)
JiangminTrojan/JboxGeneric.grz
WebrootW32.Malware.Heur.Dkvt
Antiy-AVLTrojan/Generic.ASMalwS.86857C
MicrosoftTrojan:Win32/Occamy.C29
ViRobotTrojan.Win32.Z.Agent.262144.YR
GDataTrojan.Generic.13150063
CynetMalicious (score: 100)
McAfeeArtemis!1364BD81198A
VBA32Trojan.Ymacco
MalwarebytesMalware.AI.4163068122
TrendMicro-HouseCallTROJ_GEN.R002H09KQ21
RisingTrojan.Tilken!8.F605 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZexaF.34182.qqW@aeCRh8si
Cybereasonmalicious.1198ad

How to remove Malware.AI.4163068122?

Malware.AI.4163068122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment