Malware

Malware.AI.4287606466 (file analysis)

Malware Removal

The Malware.AI.4287606466 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4287606466 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Malware.AI.4287606466?


File Info:

name: 11F261CDB6CED37DC25B.mlw
path: /opt/CAPEv2/storage/binaries/aa0f3f67b9c68ef10c25a5badaece7796d30bdcec6b60e6a62931c9d913d6805
crc32: 9FA01DB2
md5: 11f261cdb6ced37dc25b40b750c65b80
sha1: 20731151e68699b815287189f655468f60c88077
sha256: aa0f3f67b9c68ef10c25a5badaece7796d30bdcec6b60e6a62931c9d913d6805
sha512: 75dfe79845bbf45b91b429094f74c32db107bb40ac46d2b61f06578a0615d68ea3d53284190031b9fbd45cdad124c28ea6dc89585aa941641de05fb70a9819a7
ssdeep: 49152:1ppWi/zuQ5+smTKh01+kYr21/Oga/qc8vytPerhNtLpCyqSMVCjOm/d:1ppBux1Sr2Da/MakZ+SMVCB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4C523C2A38588F6F3E4117024A75F769E35E18D4D14CA87F3DCEDFA96271A0A42278D
sha3_384: 75896e344ee0c611d241a8b1dbc29b96b3d6fc7be3592b2c87837f0fc128fad2660423a00fa938f9092dc8642df787ab
ep_bytes: 558bec6aff68b092430068c462430064
timestamp: 2018-11-28 07:21:03

Version Info:

CompanyName: HeavenWard
FileDescription: FK Package 4,6,0,0
FileVersion: 4,6,0,0
LegalCopyright: © 2018, HeavenWard
Translation: 0x0409 0x04b0

Malware.AI.4287606466 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Keylogger.4!c
MicroWorld-eScanGen:Variant.Application.Keylogger.WanKey.2
FireEyeGen:Variant.Application.Keylogger.WanKey.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Wacatac.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KeyLogger.LightLogger.J.gen
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Application.Keylogger.WanKey.2
Ad-AwareGen:Variant.Application.Keylogger.WanKey.2
SophosGeneric PUA CA (PUA)
ZillyaTool.ActivityMonitor.Win32.2
EmsisoftGen:Variant.Application.Keylogger.WanKey.2 (B)
GDataGen:Variant.Application.Keylogger.WanKey.2
JiangminMonitor.BestKeyLogger.c
WebrootW32.Keylogger.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
ALYacGen:Variant.Application.Keylogger.WanKey.2
MalwarebytesMalware.AI.4287606466
IkarusPUA.KeyLogger.Lightlogger
eGambitUnsafe.AI_Score_99%
PandaHacktool/Keylogger

How to remove Malware.AI.4287606466?

Malware.AI.4287606466 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment