Malware

Malware.AI.4175630645 (file analysis)

Malware Removal

The Malware.AI.4175630645 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4175630645 virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.4175630645?


File Info:

name: B9B646C5F3D0C4F65C03.mlw
path: /opt/CAPEv2/storage/binaries/e115afd2815e65edb2fb3518d72cd1ae565434dc25872bd6e497e5ad4535de23
crc32: A5F63CFD
md5: b9b646c5f3d0c4f65c0349879d7c1731
sha1: c1398c3cdfaf94057521a0fdcf2a5b7fc292ab5a
sha256: e115afd2815e65edb2fb3518d72cd1ae565434dc25872bd6e497e5ad4535de23
sha512: eacba7315eef3ef2fa8ed1fe05099ed7ec7159d2ac2a5e8483688bcdff324ff0f2e99bce9588b3ee587ca7519a236d6e6047288b81960035b60f63bf59f2c38f
ssdeep: 24576:Erm1rxy4bPoq958nXgHoMOnkg4Z0TBoOHce0gw7R57wxsB7Eaz0PO0N46lN:EKFxy4bAqHWgHCkNwiPgaJFBEazc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9C5F028BB99D503EAAA6374CE67C6F68B313D156C52C20B32447F6F3771393A961306
sha3_384: 4241f8a1a11f89c9550f1093151669e5c1df424376a72f9495f9695fe1b934dfe6d940fea5f84064dd048c9a65b4fa22
ep_bytes: ff25006094005d000000019f03000040
timestamp: 2051-07-08 23:30:34

Version Info:

Translation: 0x0000 0x04b0
Comments: Hassani Stopper v1.0 By ALi Hassani +212676866794
CompanyName: Hassani Stopper v1.0 By ALi Hassani +212676866794
FileDescription: Hassani Stopper v1.0 By ALi Hassani +212676866794
FileVersion: 1.0.0.0
InternalName: Hassani Stopper v1.0 By ALi Hassani +212676866794.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: Hassani Stopper v1.0 By ALi Hassani +212676866794.exe
ProductName: Hassani Stopper v1.0 By ALi Hassani +212676866794
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.4175630645 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31366402
FireEyeGeneric.mg.b9b646c5f3d0c4f6
McAfeeArtemis!B9B646C5F3D0
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e2ec1 )
AlibabaTrojan:MSIL/Generic.00121caf
K7GWTrojan ( 0055e2ec1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.B
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
BitDefenderTrojan.Generic.31366402
Ad-AwareTrojan.Generic.31366402
EmsisoftTrojan.Generic.31366402 (B)
SophosMal/Generic-S
Paloaltogeneric.ml
GDataWin32.Trojan.Agent.DPJXXR
AviraHEUR/AGEN.1138991
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4239106
BitDefenderThetaGen:NN.ZemsilF.34114.Gw0@a0g8!fo
ALYacTrojan.Generic.31366402
MAXmalware (ai score=86)
MalwarebytesMalware.AI.4175630645
TrendMicro-HouseCallTROJ_GEN.R053H0CA422
RisingMalware.Obfus/MSIL@AI.85 (RDM.MSIL:Zt/JM2A9y3ItBPtsn4Za0Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Malware.AI.4175630645?

Malware.AI.4175630645 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment