Malware

Malware.AI.4281177374 information

Malware Removal

The Malware.AI.4281177374 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4281177374 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.4281177374?


File Info:

name: 8B1E3ED74FEB19AA5C40.mlw
path: /opt/CAPEv2/storage/binaries/ac76a5e09a6c91ed89ac0d91574c2bca57e95e27e75c8a704c05eda25f2c2191
crc32: F1DD27D7
md5: 8b1e3ed74feb19aa5c40318fcb4593e0
sha1: 65770d22b775e1ae13fe1e437ea7619755ea60ed
sha256: ac76a5e09a6c91ed89ac0d91574c2bca57e95e27e75c8a704c05eda25f2c2191
sha512: ea8a7cf2f237f5eba6c888771bd1201e3e23448cb60e21d327b51b22483aeed7550788a40f07a691ca701a4d50c3d0da3d34d9eadf4a9a09a2428ce74541d51f
ssdeep: 49152:HBuZrEUHxvGCfwhgPSVjAi1zMbVoClyTuof3GU9QbKzjgZTUljE8K:hkLRvGCfwh9yi2CClOG2Qez8IjE8K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AF5F13BF268A13ED86A0A32457392509A7B7E61A81A8C1F17FC350CCF775701E3B656
sha3_384: 2205775a067760c5eebfca1b1047e2252a60c5ae07876b98a6e72d58cc4ec3d6972f4623322112dd3d652a6e7c0d14e2
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: SpecterOps Inc.
FileDescription: SHService Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: SHService
ProductVersion: v2.1.7
Translation: 0x0000 0x04b0

Malware.AI.4281177374 also known as:

BkavW32.Common.E612BD6E
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.69486679
FireEyeTrojan.GenericKD.69486679
SkyhighArtemis!Trojan
McAfeeArtemis!8B1E3ED74FEB
MalwarebytesMalware.AI.4281177374
VIPRETrojan.GenericKD.69486679
K7AntiVirusRiskware ( 0058f4171 )
BitDefenderTrojan.GenericKD.69486679
K7GWRiskware ( 0058f4171 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Riskware.SharpHound.A
SophosGeneric Reputation PUA (PUA)
EmsisoftTrojan.GenericKD.69486679 (B)
IkarusTrojan.SuspectCRC
MAXmalware (ai score=87)
ArcabitTrojan.Generic.D4244857 [many]
GDataTrojan.GenericKD.69486679
ALYacGeneric.Trojan.Hound.Marte.A.734FF4EA
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
MaxSecureTrojan.Malware.218665841.susgen
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Malware.AI.4281177374?

Malware.AI.4281177374 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment