Malware

What is “Malware.AI.4269701098”?

Malware Removal

The Malware.AI.4269701098 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4269701098 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (10 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Network anomalies occured during the analysis.
  • Starts servers listening on 127.0.0.1:0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to disable Windows Defender
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

sokiran.xyz
ezcube.ru
ip-api.com
ezstat.ru
cor-tips.com
www.facebook.com
apps.identrust.com
bandakere.tumblr.com
iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
email.yg9.me
www.waaer435fc.com
iw.gamegame.info
ol.gamegame.info
uehge4g6gh.2ihsfa.com

How to determine Malware.AI.4269701098?


File Info:

crc32: 805B3303
md5: 21500b8f26a794e243db18e50b19604f
name: 21500B8F26A794E243DB18E50B19604F.mlw
sha1: 026efe006209bb1b0da8da054f0d3a6c3080eecd
sha256: 9f502d67a0bf8c88a2569789a6ac21bd3bf80840b5eabcabffb6c493f7ba475e
sha512: 9edcf82233c2b60426933c963a2ff733234f415923f47677b795566347e0b7af49ada81f0c060d38b8527b66df9422b131af598ca65a86ef1a4b83c39eea69db
ssdeep: 98304:xECvLUBsgUtB/0BW1jiGDDU1Eq8hlHefLFK1d/8J:xZLUCgQZ0U1jiG/U1Eq87efc1dUJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
InternalName: 7zS.sfx
FileVersion: 19.00
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 19.00
FileDescription: 7z Setup SFX
OriginalFilename: 7zS.sfx.exe
Translation: 0x0409 0x04b0

Malware.AI.4269701098 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Inject4.12633
CynetMalicious (score: 99)
CAT-QuickHealPUA.IgenericRI.S15903427
ALYacTrojan.Agent.Raccoon
CylanceUnsafe
SangforTrojan.Win32.CookiesStealer.b
AlibabaTrojanDownloader:Win32/CookiesStealer.395bb018
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f26a79
CyrenW32/Trojan.RPME-3372
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
AvastWin32:Malware-gen
ClamAVWin.Packed.Barys-9859531-0
KasperskyTrojan.Win32.CookiesStealer.b
BitDefenderGen:Variant.Jaik.45703
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
MicroWorld-eScanGen:Variant.Jaik.45703
Ad-AwareGen:Variant.Jaik.45703
SophosMal/Generic-R
F-SecureHeuristic.HEUR/AGEN.1138963
BitDefenderThetaGen:NN.ZedlaF.34738.n88baOE@FOp
TrendMicroTROJ_GEN.R002C0WFE21
McAfee-GW-EditionGenericRXNE-CG!4915242C4106
FireEyeGen:Variant.Jaik.45703
EmsisoftGen:Variant.Jaik.45703 (B)
JiangminTrojanSpy.Fbkatz.g
AviraTR/AD.Inject.sewyr
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.33776E5
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.RM!MTB
ArcabitTrojan.Jaik.DB287
AegisLabTrojan.Win32.CookiesStealer.4!c
ZoneAlarmHEUR:Trojan.Win32.Kryplod.gen
GDataGen:Variant.Jaik.45703
AhnLab-V3Malware/Win.Generic.C4526467
McAfeeArtemis!21500B8F26A7
MAXmalware (ai score=82)
VBA32BScope.Trojan.Injector
MalwarebytesMalware.AI.4269701098
PandaTrj/CI.A
RisingTrojan.Generic@ML.88 (RDML:y7CnJnqDA1GnKTVXfSQh2g)
IkarusEICAR-Test-File
FortinetW32/GenKryptik.FGIF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.4269701098?

Malware.AI.4269701098 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment