Malware

What is “Malware.AI.4210225086”?

Malware Removal

The Malware.AI.4210225086 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4210225086 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Clears web history

How to determine Malware.AI.4210225086?


File Info:

name: C261A9090FD2E7D5AD61.mlw
path: /opt/CAPEv2/storage/binaries/fdee5ba6c5ea4393157d18cabf482fd61ce31ec0ea327a6580f2d583f2c3cad8
crc32: B1790FB5
md5: c261a9090fd2e7d5ad6102fe85a61f68
sha1: e7f2f33ec45eed818df278beb80adbe4b61c7ade
sha256: fdee5ba6c5ea4393157d18cabf482fd61ce31ec0ea327a6580f2d583f2c3cad8
sha512: 24f56d77244485fe9f00d9a987979c725fb56264a9a97cd37640ee51aca2202cb8361ec687eb951d8f48e523023c1287d2efaf246572341ae161817985337e9f
ssdeep: 768:DZqRDF4mkWQfcwGHAfaodnpAHK+f2vV+dBxhvL4YhR4zXOoXrlE:DZmpQEjHKtn0zOd+dphR4rnZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BC3027738D906A7CACF1C7464535436EAB61F24A3D486A4CB80A32F4F3674DE816F09
sha3_384: 71a843f4326fd0871ed3052672d1959ae9a022e60fe948b6799bfc630a82d10d9ecb5f533cdc404a6d0421e4216eb68d
ep_bytes: 0f9fc39966be21a7660fca64a1300000
timestamp: 2005-07-30 10:56:51

Version Info:

CompanyName: †SOFTWIN龝爋䉾᭓잉똴
拳꺋麘쓻ヲ⎖펞뱠᫅○璭⨡鿚䧱午鏳氐䯺혿줉ꗡឯꦢꠕ᭷꒒ud8ceࣗΎ뒗繢㔨㿣
쥉䗧ျ뮱힡ᗟ販蘏鏊밞柠籀쭂udf6b껉嬘蘀Ჱ於搽ﴑﯸ䰾퐕댂禷뒖踕፭測麬ੌ沒뢽靓畈蛓作ᱷ䏧羢籀䎉毌䙪햬햝鳲ꄕ맃udf1f命뷶菮啐໕ֿỒ膆げ㔍㩏Ꮾⓥꑔ섶㗱ɏ抂寫쩅욲읐蚸⇀ẫ틊浜弎詷事쏻ᤗ⿬ud8d7ᯢ◜蕢ⳙ眳玀爝࣠⦻න䱌ᮩ쬹笢㌂뛗飯Ẓ쓣udf75uda4bꥐபudb9d㱷㿓뫒쁊刉ud94aꎱ븈㱟溞崆㽙膒郉ࡊ鲀雲띺᫟抁癛䐌ᾆ䝔迏宾캌ᘂ禒嬪왟駩䂖由㻥ྀudcbb㊜惂ᮎ娋鰦졝چ荒犑袽╖찚੕凗䈸쵢깿뻉ై쁉⊀倜먒䌼廅ꨄᏼ馂뫒ud8d1㫳䎔〪ᐤȷꃔ䪄᳟㳀㔔欐別餱Ԓኽ郜䤧⢋₃똺롬⣩៺툸䤗燆㐷맳哬蠬뫥帺ꄓꘊ䍘쀟땽旍ᄌ흵㤚偭㼼浸敶獲潩㵮ㄢ〮•湥潣楤杮∽呕ⵆ∸猠慴摮污湯㵥礢獥㼢ാ㰊獡敳扭祬砠汭獮∽牵㩮捳敨慭⵳業牣獯景⵴潣㩭獡⹭ㅶ•慭楮敦瑳敖獲潩㵮ㄢ〮㸢਍†愼獳浥汢䥹敤瑮瑩൹ ††瘠牥楳湯∽⸱⸰⸰∰਍†††牰捯獥潳䅲捲楨整瑣牵㵥堢㘸ഢ ††渠浡㵥䴢物湡慤䴮物湡慤䴮物湡慤ഢ ††琠灹㵥眢湩㈳ഢ ⼠ാ 㰠敤捳楲瑰潩㹮䥑㱐搯獥牣灩楴湯ാ 㰠牴獵䥴普浸湬㵳產湲猺档浥獡洭捩潲潳瑦挭浯愺浳瘮∲ാ †㰠敳畣楲祴ാ ††㰠敲畱獥整偤楲楶敬敧㹳਍††††爼煥敵瑳摥硅捥瑵潩䱮癥汥਍†††††敬敶㵬愢䥳癮歯牥ഢ ††††甠䅩捣獥㵳昢污敳⼢ാ ††㰠爯煥敵瑳摥牐癩汩来獥ാ †㰠猯捥牵瑩㹹਍†⼼牴獵䥴普㹯਍⼼獡敳扭祬>:

Malware.AI.4210225086 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c261a9090fd2e7d5
CAT-QuickHealTrojanPWS.Zbot.Y10
McAfeePWS-Zbot.gen.avx
CylanceUnsafe
VIPRETrojan.Win32.Zbot.im (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
AlibabaTrojan:Win32/Kryptik.2af17899
K7GWTrojan ( 005110401 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.BLFB
CyrenW32/FakeAlert.OG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ASLG
APEXMalicious
ClamAVWin.Trojan.4965888-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor[Softwin]
MicroWorld-eScanTrojan.Brsecmon.1
AvastWin32:MalOb-CK [Cryp]
TencentWin32.Trojan.Generic.Swkf
Ad-AwareTrojan.Brsecmon.1
EmsisoftTrojan.Brsecmon.1 (B)
ComodoPacked.Win32.Krap.hd@2nkc7n
DrWebTrojan.PWS.Panda.487
ZillyaTrojan.Zbot.Win32.50227
TrendMicroTROJ_KRYPTK.SMM
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SophosMal/Generic-R + Mal/Zbot-IM
SentinelOneStatic AI – Malicious PE
GDataTrojan.Brsecmon.1
JiangminTrojan/Generic.bdop
WebrootW32.InfoStealer.Zeus
AviraTR/Drop.Agent.awd.8
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Brsecmon.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.hW0@aapLbngI
ALYacTrojan.Brsecmon.1
VBA32Trojan.Zeus.EA.01000
MalwarebytesMalware.AI.4210225086
TrendMicro-HouseCallTROJ_KRYPTK.SMM
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!82C/2Sb/pGI
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.1487117.susgen
FortinetW32/Kryptik.AJ!tr
AVGWin32:MalOb-CK [Cryp]
Cybereasonmalicious.90fd2e
PandaGeneric Malware

How to remove Malware.AI.4210225086?

Malware.AI.4210225086 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment