Malware

Malware.AI.4266721123 (file analysis)

Malware Removal

The Malware.AI.4266721123 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4266721123 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.4266721123?


File Info:

name: 9092DC2AF61F8A079EEB.mlw
path: /opt/CAPEv2/storage/binaries/9b8bbdd315ffc8a21b3bf150dafb4d7dee4e1922c12e3c06fceb7214a343dd2b
crc32: 88A78BEB
md5: 9092dc2af61f8a079eebacc71e52675f
sha1: 4b72dc13b59e37da4bed941f6e5ab806237daa91
sha256: 9b8bbdd315ffc8a21b3bf150dafb4d7dee4e1922c12e3c06fceb7214a343dd2b
sha512: c0b260eeb176928099834f4104a64fa0a14b8de2051ee47606d42cdc9c00038a4073d866672603e827f9854b0978cec4afc8d73d0ea3d1c4e51237d7fb552355
ssdeep: 12288:+6njgFsQpjL8ffA0qKOvmkG5uMQ05uUWlVls5d0VrsXioS:+6ZcLZKOvRpeHWejj
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1D1B4238BBB2FED9DE00D28782F5BB4283CD1D9543F945D574AD04223DC776A96C700A6
sha3_384: 3bbe36b8bc99505aa6f3973e59bc5309dfa2e681f5004a1f44d6a0d246a532d27a735baac7654d2d57108adc2b202b4b
ep_bytes: 807c2408010f85d90b000060be00c00d
timestamp: 2023-09-23 07:59:18

Version Info:

0: [No Data]

Malware.AI.4266721123 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Mikey.161686
FireEyeGen:Variant.Mikey.161686
SkyhighBehavesLike.Win32.Generic.hc
McAfeeRDN/Generic.grp
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4506612
SangforTrojan.Win32.Kryptik.V2lt
K7AntiVirusTrojan ( 005ac13a1 )
AlibabaTrojan:Win32/Kryptik.bbe3464c
K7GWTrojan ( 005ac13a1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HUUR
CynetMalicious (score: 100)
BitDefenderGen:Variant.Mikey.161686
AvastWin32:Malware-gen
TencentWin32.Trojan.Kryptik.Qnkl
EmsisoftGen:Variant.Mikey.161686 (B)
F-SecureTrojan.TR/AD.Farfli.deapc
VIPREGen:Variant.Mikey.161686
TrendMicroTROJ_GEN.R002C0PAU24
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Mikey.161686
GoogleDetected
AviraTR/AD.Farfli.deapc
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Mikey.D27796
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGen:Variant.Mikey.161686
MAXmalware (ai score=87)
MalwarebytesMalware.AI.4266721123
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PAU24
RisingBackdoor.Agent!8.C5D (TFE:6:Pz7P26Wz67)
MaxSecureTrojan.Malware.230379030.susgen
FortinetW32/Kryptik.HMVR!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.4266721123?

Malware.AI.4266721123 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment