Malware

Malware.AI.4253683409 (file analysis)

Malware Removal

The Malware.AI.4253683409 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4253683409 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Created a process from a suspicious location
  • A script process created a new process

How to determine Malware.AI.4253683409?


File Info:

name: 58599439CA23B04FA832.mlw
path: /opt/CAPEv2/storage/binaries/ab6eaa64e4136d717511060c49a60ecc17a4eaba30d8b61c1d78a17f99c69b93
crc32: C3950D29
md5: 58599439ca23b04fa832f435f266d74b
sha1: e3283a2c1616099342c1892353893992f23a4369
sha256: ab6eaa64e4136d717511060c49a60ecc17a4eaba30d8b61c1d78a17f99c69b93
sha512: 25cd1993cd1d32c553b5eae3d604cf27a1391437189e43da77214b46dd2d155212fe1caf980e583a25e0530ea8fb52b2f552067ba17f1a8d8d490c154a62cc06
ssdeep: 12288:0Qnk3GDYKGcblwtX+t4Y8n9WmPzEhfvSk8ClJ1IM8xSvSDJeIw1kayeD7u45:IAOcZwXYFmLOvSx1hPAPJD7uI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121F40201BBD1C8B1D5731D325A29AB156D3C7D306E38DA6FA3D42D2ECA351C0A635BA3
sha3_384: 6886e6cbc3633c6865dd11dfd94c45ee7ca109d73041ac19fa3e1ef75be37d736f26ac85981db8e4dbccbb25361e95a7
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Malware.AI.4253683409 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.PowerShell.4!c
MicroWorld-eScanIL:Trojan.MSILZilla.11883
FireEyeGeneric.mg.58599439ca23b04f
ALYacIL:Trojan.MSILZilla.11883
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/PowerShell.b1653775
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.2
Paloaltogeneric.ml
KasperskyTrojan.Win32.PowerShell.czc
BitDefenderIL:Trojan.MSILZilla.11883
AvastWin32:Malware-gen
EmsisoftIL:Trojan.MSILZilla.11883 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosMal/Generic-S
MaxSecureWin.MxResIcn.Heur.Gen
AviraTR/PShell.urvkf
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataMSIL.Backdoor.ASyncRAT.80SOK8
CynetMalicious (score: 100)
McAfeeArtemis!58599439CA23
MAXmalware (ai score=88)
VBA32Trojan.PowerShell
MalwarebytesMalware.AI.4253683409
APEXMalicious
AVGWin32:Malware-gen

How to remove Malware.AI.4253683409?

Malware.AI.4253683409 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment