Malware

About “Malware.AI.4169346327” infection

Malware Removal

The Malware.AI.4169346327 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4169346327 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.4169346327?


File Info:

name: 151700A1D591F048CB8F.mlw
path: /opt/CAPEv2/storage/binaries/ab115ac8468e4cad41d59a56f851f577418ed9c56e5f9d007dc6bba86e2a86bd
crc32: CAD3A91A
md5: 151700a1d591f048cb8f51ff85e10743
sha1: 08952ceb5ccab71153459320fdfb6457ead8a95f
sha256: ab115ac8468e4cad41d59a56f851f577418ed9c56e5f9d007dc6bba86e2a86bd
sha512: 4427a983e09c1172502f6d323f50b8484c406ee9080c028cd13d365eb4a7197cdc27b36bfe3cfd3cdb6751c6d8da27413afba097bb70e493a2bd3db6ccfef4f9
ssdeep: 768:Ko19pMaSJrCd3EHeH+OZdEdU3+HreVFb7tpZ/rd+a:Ko1HGkYkEm9j/trzd+a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5F2D190E49609D2FAD309F366B283FB5F633915176A417EB9A8071DBF73D340A0B161
sha3_384: 87a54a9a107b169911a81d3c308e0ff8b56914366d815f385fa7a026d819ad0e765f5ba112e45be62b8bbe77957948a4
ep_bytes: b8e42342005064ff3500000000648925
timestamp: 2021-08-20 08:39:35

Version Info:

Translation: 0x0409 0x04b0
Comments: Fucking Hooman
CompanyName: Hikarahikaru
FileDescription: Hikarahikaru
LegalCopyright: Hikarahikaru
LegalTrademarks: Hikarahikaru
ProductName: Hikarahikaru
FileVersion: 1.00
ProductVersion: 1.00
InternalName: HHKISBACKNEW
OriginalFilename: HHKISBACKNEW.exe

Malware.AI.4169346327 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
McAfeeGenericRXAA-FA!151700A1D591
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusNetWorm ( 700000151 )
AlibabaTrojan:Win32/Generic.fb7b0af9
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.1d591f
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Trojan.Heur.ci0fb1@rp4ai
MicroWorld-eScanGen:Trojan.Heur.ci0fb1@rp4ai
Ad-AwareGen:Trojan.Heur.ci0fb1@rp4ai
SophosGeneric ML PUA (PUA)
FireEyeGen:Trojan.Heur.ci0fb1@rp4ai
EmsisoftGen:Trojan.Heur.ci0fb1@rp4ai (B)
IkarusTrojan.Crypt
GDataGen:Trojan.Heur.ci0fb1@rp4ai
AviraTR/Crypt.CFI.Gen
MAXmalware (ai score=85)
ArcabitTrojan.Heur.EEB4ED
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Crypt.C4129545
ALYacGen:Trojan.Heur.ci0fb1@rp4ai
MalwarebytesMalware.AI.4169346327
TrendMicro-HouseCallTROJ_GEN.R002H09HO21
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
BitDefenderThetaAI:Packer.C893A9861C
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.4169346327?

Malware.AI.4169346327 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment