Malware

About “Malware.AI.4276507141” infection

Malware Removal

The Malware.AI.4276507141 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4276507141 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Enumerates running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.4276507141?


File Info:

name: 6DA45EEC69757F4C74FF.mlw
path: /opt/CAPEv2/storage/binaries/34f109a9ada948012849bf721d938c965d75651daf43237091f66e113f8057dc
crc32: BD1A17F1
md5: 6da45eec69757f4c74ff6b0c6177155f
sha1: e925f3f82f243ecd18914c172a1736da596e7b2c
sha256: 34f109a9ada948012849bf721d938c965d75651daf43237091f66e113f8057dc
sha512: 725ec03681fafd6514b405549370f01194745b3d9ffcc2bdf903eabea879bf72f89aa294b175b8bd1b272cb170cb28e4770a14468e15cbbabfb9eaf15ab16666
ssdeep: 49152:o2cJ16axGGke3z/jsNsKAY/ZiF7I5TY6LG7yGtW/hx37564sx/UcE7C6OgJksqvQ:W6y3tj4NlAYhS7IHeYvV6Tgy73
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1FA1633D3BA8C54A4E86A913428BC0C05967ABD7E4D441E7EBADE7B0E98F74F04052F53
sha3_384: 4e34684a9e878b672937db9ff6b77d9b293e57b6c3ff1a5ea672b1c4cd695bf267b85bf14fd9cb654c19612a44d2fc61
ep_bytes: 57565351524150488d054f030000488b
timestamp: 2020-04-20 08:29:37

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Internet Explorer
FileVersion: 11.00.22000.120
InternalName: iexplore
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: IEXPLORE.EXE
ProductName: Internet Explorer
ProductVersion: 11.00.22000.120
Translation: 0x0409 0x04b0

Malware.AI.4276507141 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.81351
FireEyeTrojan.GenericKDZ.81351
ALYacTrojan.GenericKDZ.81351
CrowdStrikewin/malicious_confidence_60% (W)
Paloaltogeneric.ml
BitDefenderTrojan.GenericKDZ.81351
AvastWin64:Malware-gen
Ad-AwareTrojan.GenericKDZ.81351
DrWebTrojan.MulDrop19.7776
McAfee-GW-EditionBehavesLike.Win64.Dropper.wc
EmsisoftTrojan.GenericKDZ.81351 (B)
GDataTrojan.GenericKDZ.81351
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!6DA45EEC6975
MAXmalware (ai score=88)
VBA32Trojan.MulDrop
MalwarebytesMalware.AI.4276507141
TrendMicro-HouseCallTROJ_GEN.R002H09L921
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin64:Malware-gen

How to remove Malware.AI.4276507141?

Malware.AI.4276507141 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment