Malware

What is “Malware.AI.4230206953”?

Malware Removal

The Malware.AI.4230206953 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4230206953 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities to create a scheduled task
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Deletes executed files from disk
  • Detected Armadillo packer using a known mutex
  • Detected Armadillo packer using a known registry key
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.4230206953?


File Info:

name: 59A174C2A5B8F671C469.mlw
path: /opt/CAPEv2/storage/binaries/982813cf36251b52f00eb3f7a052d5c20ce0894780e095b2a2d22204b8218aed
crc32: D71404BB
md5: 59a174c2a5b8f671c469b26b9b84517e
sha1: 9b60140fdd10fb67041f59470f0b7638871d0708
sha256: 982813cf36251b52f00eb3f7a052d5c20ce0894780e095b2a2d22204b8218aed
sha512: d756562605449fe9b99484ab430faa948f6a5ded4e9c1ac94f6d37bece1567606d109b895ef1ca28e24f0093a6588e71c1cc1b83ac9192d8417f8cb06e92032f
ssdeep: 49152:HPTyMjSTHSbD8Zo/X+ZyO7jDiZ9BxvwuxOSjmJ5GB0:vmM4iDW2uZH7jpCU5GO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159A5BF21A250C137E7E319B49A3D52BD152E3E72AC65D017B3CCFF8E1A316D59A22723
sha3_384: 69c2805929014b9bb35bb049ef55dd60b53be4fb852ae480f0e271dc9709c2fe9b3264596ddf226da3b638bc52488d94
ep_bytes: 60e8000000005d50510fcaf7d29cf7d2
timestamp: 2019-07-30 08:52:50

Version Info:

Translation: 0x0000 0x04e4

Malware.AI.4230206953 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
SkyhighArtemis!Trojan
MalwarebytesMalware.AI.4230206953
SangforTrojan.Win32.Agent.Vhcp
Cybereasonmalicious.fdd10f
BitDefenderThetaGen:NN.ZexaE.36792.bMW@aW8P@Ym
VirITTrojan.Win32.Generic.AQFG
tehtrisGeneric.Malware
CynetMalicious (score: 99)
APEXMalicious
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Injector.Win32.231732
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!59A174C2A5B8
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Agent.TV
TrendMicro-HouseCallTROJ_GEN.R002H0CEB23
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.4230206953?

Malware.AI.4230206953 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment