Malware

Malware.AI.4246227004 removal

Malware Removal

The Malware.AI.4246227004 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4246227004 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Fake User-Agent detected
  • CAPE detected the CobaltStrikeBeacon malware family
  • Attempts to modify proxy settings

How to determine Malware.AI.4246227004?


File Info:

name: 6E7466E3071BFEC88B10.mlw
path: /opt/CAPEv2/storage/binaries/eb26701fb4f7c7d5ef8cd27a4f655ae914d47e961f2c6f8a3aae1e1d723d73d1
crc32: 8DFDBB8F
md5: 6e7466e3071bfec88b1027e6e29bf912
sha1: 05ca71ceae995ea724e2bfd837f063432c684007
sha256: eb26701fb4f7c7d5ef8cd27a4f655ae914d47e961f2c6f8a3aae1e1d723d73d1
sha512: 458ff36f7d44e2825e296fdfa9c3d5e06604910979169251105875f18e748a2d525f7a4e982b0710eab11f899154fd66bd47dcd2a0d6514d71ba05a743944b97
ssdeep: 6144:tqC9jgafQRvnHbVEqfKDAj+e8H+jRvFSY8ymbown5IB:AC9UUEiDAyeJjRvAY8hc
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1B8D4381956FA1118F9F3AB3168390E14893ABCFAA839D05F314CB91D1F73A5489B4B37
sha3_384: 43d26f4df598d3cbf5bdb6cf91cf5bb5f479c9d1d5641dfb1ef997f15388b916ae9f65d611edd091f6de896078245d1d
ep_bytes: 488d6424d8c60514bd0400004c8d053d
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java Update Checker
FileVersion: 2.8.301.9
Full Version: 2.8.301.9
InternalName: Java Update Checker
LegalCopyright: Copyright © 2021
OriginalFilename: jucheck.exe
ProductName: Java Platform SE Auto Updater
ProductVersion: 2.8.301.9
Translation: 0x0409 0x04b0

Malware.AI.4246227004 also known as:

LionicTrojan.Win32.Bsymem.4!c
MicroWorld-eScanGen:Variant.Razy.849868
FireEyeGen:Variant.Razy.849868
CAT-QuickHealTrojan.Cobalt
ALYacGen:Variant.Razy.849868
CylanceUnsafe
AlibabaTrojan:Win32/Cobalt.a56a20fd
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallBackdoor.Win64.COBEACON.YXBLBZ
Paloaltogeneric.ml
KasperskyTrojan.Win32.Cobalt.hit
BitDefenderGen:Variant.Razy.849868
AvastWin64:Malware-gen
TencentWin32.Trojan.Cobalt.Wrqq
Ad-AwareGen:Variant.Razy.849868
EmsisoftGen:Variant.Razy.849868 (B)
TrendMicroBackdoor.Win64.COBEACON.YXBLBZ
McAfee-GW-EditionBehavesLike.Win64.Dropper.hh
SophosMal/Generic-S
IkarusTrojan.CobaltSC
GDataGen:Variant.Razy.849868
AviraTR/AD.CobaltSC.qtqzv
Antiy-AVLTrojan/Generic.ASMalwS.34E15FB
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
AhnLab-V3Malware/Win.Generic.C4807183
McAfeeArtemis!6E7466E3071B
VBA32Trojan.Bsymem
MalwarebytesMalware.AI.4246227004
MAXmalware (ai score=84)
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
Cybereasonmalicious.3071bf
PandaTrj/CI.A

How to remove Malware.AI.4246227004?

Malware.AI.4246227004 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment