Malware

About “Malware.AI.4213000808” infection

Malware Removal

The Malware.AI.4213000808 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4213000808 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • CAPE detected the RaccoonV2 malware family
  • Anomalous binary characteristics

How to determine Malware.AI.4213000808?


File Info:

name: 8BE55B41A2510DF0562A.mlw
path: /opt/CAPEv2/storage/binaries/cca3fce1159ff0bf0a904480e4daca9ca9f3bc5997ce0d1cd71939a0767627d5
crc32: CB1A5C3A
md5: 8be55b41a2510df0562a8cb401ce9eb2
sha1: 51204461f6e2bde29851b4088c5841d2c4c626de
sha256: cca3fce1159ff0bf0a904480e4daca9ca9f3bc5997ce0d1cd71939a0767627d5
sha512: 298e0bd8e1e64732da3eb5739c8f6e084a8d116cd88ce5041911bfd34169eeeae66b7d20ff32a2fdc58e00f2948da8e24b538cc2ac609852d6d55702814ba6bb
ssdeep: 49152:XLOdBItp61T4TjD+M0Trqt1bxssEIB8fEbriJIL5VXpG8xyM:XCdutp6Fo11bxssrCyXpGyJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEC533213BD881B5D0E102316CC42FBA54F6B566536489D727D0A22E7A3EFE0DE39297
sha3_384: 8347767d1fdcbfb8d0a60e7a8cf9a6ad07c7dc8c549e9874d65d303618fb3e1cdcf33d4dd8c2505034f19a350e8109cf
ep_bytes: 558bec6aff6810b34100684088410064
timestamp: 2016-01-14 18:28:57

Version Info:

CompanyName: Microsoft Corporation
LegalCopyright: Copyright Microsoft Corporation
OriginalFilename: msedgeupdate.dll
FileVersion: 1.3.147.37
ProductName: Microsoft Edge Update
ProductVersion: 1.3.147.37
InternalName: Microsoft Edge Update
FileDescription: Microsoft Edge Update
Created: 7z SFX Constructor v4.6.0.0 (http://usbtor.ru/viewtopic.php?t=798)
Builder: ahileeeeeess 01:12:09 05/08/2022
Translation: 0x0000 0x04b0

Malware.AI.4213000808 also known as:

K7AntiVirusTrojan ( 005715c71 )
K7GWTrojan ( 005715c71 )
Elasticmalicious (high confidence)
ESET-NOD32BAT/Starter.NHH
ClamAVWin.Adware.InstallPack-9918495-0
KasperskyTrojan-Spy.Win32.Stealer.cjlg
NANO-AntivirusTrojan.Win32.Stealer.jrcnwe
AvastFileRepMalware
McAfee-GW-EditionArtemis
Trapminesuspicious.low.ml.score
JiangminTrojan.BAT.mv
WebrootAdware.Gen
AviraTR/AD.RaccoonSteal.heseh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan-Stealer.Racealer.OXAWO3
CynetMalicious (score: 100)
McAfeeArtemis!8BE55B41A251
MalwarebytesMalware.AI.4213000808
FortinetW32/Starter.NHH!tr
AVGFileRepMalware

How to remove Malware.AI.4213000808?

Malware.AI.4213000808 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment