Malware

Malware.AI.4231699159 (file analysis)

Malware Removal

The Malware.AI.4231699159 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4231699159 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for fileless persistence
  • Exhibits possible ransomware file modification behavior
  • A script process initiated network activity
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system

How to determine Malware.AI.4231699159?


File Info:

name: FC95CFADF0B7DA33BE8A.mlw
path: /opt/CAPEv2/storage/binaries/a5530040d2c16b82baa16f36b5aebcdb50a55b9ded214f2f0b62c01e8c14f17e
crc32: A51D2CE6
md5: fc95cfadf0b7da33be8af91d3c1841f2
sha1: 2f27433b9000f962f6227fdcf40546eac76d5d68
sha256: a5530040d2c16b82baa16f36b5aebcdb50a55b9ded214f2f0b62c01e8c14f17e
sha512: cc14923759c63af7103c00acbdb5da720c5056dd7e6cb15c89bd3d124242968fe9043295f586235d31066bef2b29a7ddd5811fb7a6430a2156b1eb173c1b72ae
ssdeep: 196608:fSOxH3F1OTlub3kYbD36z1fQb3DaxNBRMN8stveF0ex0VAYCT:fSOxVIxC6OjaNB2N8stvoFQA7T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D96330F5C1AB652FB6D0B34E8D8E5BD15263D026ACE8523E8D87C5B7173041E8D1EAB
sha3_384: 23bdc223315dbbdee9eb302a890aa6be3a70b35bc2e72d4a197032593097e5f6dd0d528754ea5f015e65893012fb8b23
ep_bytes: 60be00b048008dbe0060f7ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Malware.AI.4231699159 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.lwaI
DrWebTrojan.DownLoader11.61950
MicroWorld-eScanTrojan.Generic.20490101
ALYacTrojan.Generic.20490101
CylanceUnsafe
ZillyaDropper.Binder.Win32.11818
K7AntiVirusTrojan ( 0055e3df1 )
AlibabaWorm:VBS/AutoRun.8af2e9bb
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.df0b7d
BitDefenderThetaAI:Packer.DFD329EB15
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Trojan.Generickd-3464
KasperskyWorm.VBS.AutoRun.ml
BitDefenderTrojan.Generic.20490101
NANO-AntivirusTrojan.Script.Autoit.debvea
AvastVBS:Decode-NE [Trj]
Ad-AwareTrojan.Generic.20490101
SophosMal/Generic-S
ComodoMalware@#6bh6lxl1zwkw
BaiduVBS.Trojan.Kryptik.gz
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virus.rc
FireEyeGeneric.mg.fc95cfadf0b7da33
EmsisoftTrojan.Generic.20490101 (B)
IkarusASP.Backdoor
GDataTrojan.Generic.20490101
JiangminTrojan.Script.zuw
eGambitGeneric.Malware
AviraDR/AutoIt.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASBOL.C6A4
KingsoftWin32.Troj.Generic_a.c.(kcloud)
ArcabitTrojan.Generic.D138A775
MicrosoftWorm:VBS/Jenxcus!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Zbot.R165134
McAfeeArtemis!FC95CFADF0B7
VBA32Backdoor.DarkKomet
MalwarebytesMalware.AI.4231699159
APEXMalicious
TencentVbs.Worm.Autorun.Egef
YandexTrojan.ObBot.Gen.PP
MaxSecureTrojan.Autoit.AZA
FortinetVBS/Kryptik.CF!tr
WebrootW32.Trojan.Gen
AVGVBS:Decode-NE [Trj]

How to remove Malware.AI.4231699159?

Malware.AI.4231699159 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment