Malware

Malware.AI.4292479146 (file analysis)

Malware Removal

The Malware.AI.4292479146 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4292479146 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

zipansion.com
aporasal.net

How to determine Malware.AI.4292479146?


File Info:

crc32: 89B00B13
md5: 08bbac1a222b781698e783821484a16b
name: 08BBAC1A222B781698E783821484A16B.mlw
sha1: ec7b70d1dee310736810bc75245cd6330a257bda
sha256: c6a3c29f59440e126a767df15505f9f89c589b5a36936ae1e8f66489e013d0f9
sha512: 8946c72df0d07393ca32960cdbbd54e383f8ec506703cad89cce78a435ecbfdd7f2bc180ca943fa70210f1d5c7cb3afb1f0538b5f6e8e59450eba6475ae8d366
ssdeep: 24576:NjKasxfiJacO37ftu0hvCx8eyTG5bIh7HjbfH3wcv/E4vOt:NjXsxkELftnvqB6Gqjwcvc4vO
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.4292479146 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.362401
FireEyeGeneric.mg.08bbac1a222b7816
CAT-QuickHealTrojan.Generic
Qihoo-360Win32/Trojan.Generic.HgIASOAA
McAfeeGenericRXAA-AA!08BBAC1A222B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Variant.Zusy.362401
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.a222b7
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.63e3e8a6
RisingTrojan.Generic@ML.99 (RDMK:ytFGklmvR2FxF8O2r0GK5Q)
Ad-AwareGen:Variant.Zusy.362401
SophosMal/Generic-R + Mal/HckPk-A
ComodoMalCrypt.Indus!@1qrzi1
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.DownLoader36.37835
TrendMicroTROJ_GEN.R002C0RAR21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Zusy.362401 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Ymacco.AAC6
ArcabitTrojan.Zusy.D587A1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.362401
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R364194
BitDefenderThetaGen:NN.ZexaF.34804.EnW@ameJx3n
ALYacGen:Variant.Zusy.362401
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4292479146
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EAPQ
TrendMicro-HouseCallTROJ_GEN.R002C0RAR21
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.FFP!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Malware.AI.4292479146?

Malware.AI.4292479146 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment