Malware

What is “Malware.AI.4176989958”?

Malware Removal

The Malware.AI.4176989958 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4176989958 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ubuntudns.sytes.net
get.adobe.com
www.adobe.com
thailandbbs.ddns.net
debain.servehttp.com

How to determine Malware.AI.4176989958?


File Info:

crc32: 1142754F
md5: ba1aea40182861e1d1de8c0c2ae78cb7
name: BA1AEA40182861E1D1DE8C0C2AE78CB7.mlw
sha1: f3fda6f46c7316381a65ccc26e94cb0ac448ec46
sha256: ca7cd0d3b5582ac4257c8ed31799d4fd577cdff1bf7ff018946b6284c0bbd617
sha512: d5512ae61d2b136a61a6aed8f5c9c07bab5dffa74e90df1ba88e6fc9d7b18548960e82b4c61f61970494fa0f2a4aabaf3f5e88f0da2dee840a3c7dae4a1f0bf3
ssdeep: 24576:SAT8QE+k5ojj/5Vn1SPsjFqNY1Vt7ZES2PxLz2NjE9f9xSx5BGBw6eV198:SAI+1/msRMYhmFBYT5BjX+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: daobe
FileDescription: Adobe Flash Player 18.0.0.203 Installation
FileVersion: 18.0.0.203
Comments:
CompanyName: daobe
Translation: 0x0409 0x04e4

Malware.AI.4176989958 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Xfs.b!c
DrWebTrojan.DownLoader25.11530
CynetMalicious (score: 99)
CAT-QuickHealTrojanDropper.Xfs
ALYacTrojan.GenericKD.2708043
CylanceUnsafe
SangforTrojan.Win32.Xfs.ba
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaBackdoor:Win32/Bookworm.c7c4f3da
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.018286
CyrenW32/Trojan.HCYJ-6796
SymantecBackdoor.Surge
ESET-NOD32Win32/Korplug.FQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Bookworm-5
KasperskyTrojan-Dropper.Win32.Xfs.ba
BitDefenderTrojan.GenericKD.2708043
NANO-AntivirusTrojan.Win32.Korplug.dwrjam
MicroWorld-eScanTrojan.GenericKD.2708043
TencentWin32.Trojan-dropper.Xfs.Pepm
Ad-AwareTrojan.GenericKD.2708043
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZedlaF.34058.aq4@a8SFBNe
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_PLUGX.DUKOI
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.ba1aea40182861e1
EmsisoftTrojan.GenericKD.2708043 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Xfs.a
WebrootW32.Trojan.Gen
AviraTR/Korplug.4608.12
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.32D9CAD
KingsoftWin32.Troj.Xfs.ba.(kcloud)
MicrosoftRansom:Win32/Blocker
ZoneAlarmTrojan-Dropper.Win32.Xfs.ba
GDataTrojan.GenericKD.2708043
McAfeeArtemis!BA1AEA401828
MAXmalware (ai score=100)
VBA32Trojan.Korplug
MalwarebytesMalware.AI.4176989958
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_PLUGX.DUKOI
YandexTrojan.DR.Xfs!wThGTl1mq4I
IkarusBackdoor.MSIL
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Xfs.BA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.PlugX.HgIASOkA

How to remove Malware.AI.4176989958?

Malware.AI.4176989958 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment