Malware

Malware.AI.4216259004 (file analysis)

Malware Removal

The Malware.AI.4216259004 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4216259004 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine Malware.AI.4216259004?


File Info:

name: 145D6B870BA4D5C0D261.mlw
path: /opt/CAPEv2/storage/binaries/1eeebf999ec8d8ef8faa7929cd6807150451431df8a70d556b5c7c99588b07b0
crc32: 23023FBA
md5: 145d6b870ba4d5c0d261218625599776
sha1: 669adacbec96ebe5a74f0ab631027d80b28e81eb
sha256: 1eeebf999ec8d8ef8faa7929cd6807150451431df8a70d556b5c7c99588b07b0
sha512: 8bba8391e829d01bd2ca96feaaadfe2c8999bd3ad3252f26b1be6d0b4c8582845af9a6283f0665e88b58c2369f99ff48758e9ba6223dabb2ef4328167087cdb7
ssdeep: 49152:l4alxsD4aD+EQAZvZqI2uRYzmM/qKqnobGFOMGojNLjBKS+4z1lcokk2Pm3yCL9s:l9xpEPnOil3kMDNLpcM2PmiCj2pur9e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19436F151BA819476C06316B95C3B9799AA29BF001F3C98D7B7F06F4C6B723C17839287
sha3_384: f6f52a4d36b430497853f960ede59cccbab97ae20d2e956761d65279eb9cc8c9ae9c85ebab4a8d63db304ba38f842765
ep_bytes: 558bec83c4f053b8d8194d00e8ef48f3
timestamp: 2012-01-09 08:07:12

Version Info:

0: [No Data]

Malware.AI.4216259004 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Bifrose-17928
FireEyeGeneric.mg.145d6b870ba4d5c0
McAfeeGenericRXRK-GC!145D6B870BA4
CylanceUnsafe
Cybereasonmalicious.bec96e
BitDefenderThetaGen:NN.ZelphiF.34182.@NZ@aKK9ULpj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.DRMSoft.B suspicious
CynetMalicious (score: 100)
RisingMalware.Bitrepeyu!8.10839 (TFE:5:RxJvTBb4hL)
SophosGeneric ML PUA (PUA)
DrWebBackDoor.Bifrost.15005
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
APEXMalicious
Antiy-AVLTrojan/Generic.ASMalwS.350BC5E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Win.GC.R466161
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4216259004
YandexRiskware.DRMSoft!7KXjnqAtXPY
IkarusPUA.DRMSoft
eGambitUnsafe.AI_Score_100%
FortinetRiskware/DRMSoft
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]

How to remove Malware.AI.4216259004?

Malware.AI.4216259004 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment