Malware

What is “Malware.AI.4218156732”?

Malware Removal

The Malware.AI.4218156732 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4218156732 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Malware.AI.4218156732?


File Info:

name: 8EAAA9DCD3CB8ED0F4E2.mlw
path: /opt/CAPEv2/storage/binaries/feb10f8224cfccab17199814df00f5a9e904e5bf32172e04f0fde5400311e4c2
crc32: 228581A7
md5: 8eaaa9dcd3cb8ed0f4e2b88a2cba93eb
sha1: ea90cd0e4f38a2ff85bcbfdf69e7676f3bcee3d6
sha256: feb10f8224cfccab17199814df00f5a9e904e5bf32172e04f0fde5400311e4c2
sha512: a4a17356e93ecee5e52c3493a9d382902607d471bdcbbba5a9aa1b67b8cddd7226349f7643794c953bc8d61661cf15fd1f09f3a13bf54059a4e47ccb09b22036
ssdeep: 49152:egmTaXiTcN6hkymAUytfYkIbbWRsAp5QGLDWJOYUftXKg0+PLz:egVyw8hFzUufDUqxp59nWD8fPLz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157B50171A6E18471E0923AF088956A6A963DBF240B23CCD752B43E167F785D3CD313AD
sha3_384: e307b6d344994c1bc12877a921cfc45fcd39633e0d99ba7dfaf6a19dcb9ec64f0b4a95efd516eb0018052571dfe9b8a6
ep_bytes: 686c060000680000000068e8ba6400e8
timestamp: 2015-10-01 06:41:32

Version Info:

Translation: 0x0004 0x03a8

Malware.AI.4218156732 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Fugrafa.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.78040
FireEyeGeneric.mg.8eaaa9dcd3cb8ed0
McAfeeGenericRXAA-AA!8EAAA9DCD3CB
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
Cybereasonmalicious.cd3cb8
ArcabitTrojan.Fugrafa.D130D8
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/HackTool.KMSAuto.E potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Fugrafa.78040
AvastFileRepMetagen [PUP]
TencentWin32.Trojan.Ramnit.Eerq
Ad-AwareGen:Variant.Fugrafa.78040
SophosGeneric PUA OK (PUA)
ZillyaAdware.OutBrowse.Win32.73156
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
EmsisoftGen:Variant.Fugrafa.78040 (B)
IkarusPUA.HackTool.Kmsauto
WebrootPUA.Gen
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Ditertag.A
GDataGen:Variant.Fugrafa.78040
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34712.wwX@aexl37bG
ALYacGen:Variant.Fugrafa.78040
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4218156732
TrendMicro-HouseCallTROJ_GEN.R002H09AD21
RisingTrojan.Generic@AI.100 (RDML:su+q3uvCrWlI4VhLLCka5w)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73692777.susgen
AVGFileRepMetagen [PUP]
PandaTrj/GdSda.A

How to remove Malware.AI.4218156732?

Malware.AI.4218156732 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment