Malware

Malware.AI.481831498 malicious file

Malware Removal

The Malware.AI.481831498 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.481831498 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Malware.AI.481831498?


File Info:

name: B5FCA8FB8629A77BD262.mlw
path: /opt/CAPEv2/storage/binaries/c0df1f26d87fba9c76c29c2c88696ffee5b8da5987859d657f7a6a61900fa63b
crc32: 60617055
md5: b5fca8fb8629a77bd2623a6a6197b85f
sha1: 0bcb0f24932e7250f294479be2f88974f68b5434
sha256: c0df1f26d87fba9c76c29c2c88696ffee5b8da5987859d657f7a6a61900fa63b
sha512: 841886ec5383f411713d1b7ae652c0616010e976e8c63ed7e4430880fa8428115217f062c93cf6917f2f9ab2b9433a3ed66d0336a1174b76d0eb771594798044
ssdeep: 1536:WNhvbJE9Tp3ke81+Hc0sWjcdKY08midgzIE08midgzIh4ht/kyGbdOwRCvv8pRqE:Wn0hO+KKYJmpJmye/kyGBOwsvaRqfM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2E3AF1036D5C4B2E5724A3509B0EB418AADFD235E749D4B33D83E8E6EB56D01B34BA3
sha3_384: a41ea6680433c51b2822d636486bedb470c9a186fa8864ba79f8156b86814cff9a4f03d45b9d6129081a1d516a45a81a
ep_bytes: e80f2b0000e9000000006a1468f88a00
timestamp: 2014-12-02 11:00:06

Version Info:

0: [No Data]

Malware.AI.481831498 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebBackDoor.Kuluoz.4
MicroWorld-eScanTrojan.Downloader.JRGI
FireEyeGeneric.mg.b5fca8fb8629a77b
CAT-QuickHealTrojanDownloader.Kuluoz.AA4
McAfeeDownloader-FAII!B5FCA8FB8629
CylanceUnsafe
SangforTrojan.Win32.Zortob.H
K7AntiVirusTrojan-Downloader ( 00512adc1 )
K7GWTrojan-Downloader ( 00512adc1 )
Cybereasonmalicious.b8629a
BitDefenderThetaGen:NN.ZexaF.34698.juW@amn4!6kc
VirITTrojan.Win32.Generic.FOU
CyrenW32/Trojan.PUNE-4615
SymantecTrojan.Asprox.B
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Zortob.H
APEXMalicious
TrendMicro-HouseCallBKDR_KULUOZ.SM23
Paloaltogeneric.ml
ClamAVWin.Trojan.Downloader-64682
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JRGI
NANO-AntivirusTrojan.Win32.Kuluoz.djqpom
SUPERAntiSpywareTrojan.Agent/Gen-Zortob
AvastWin32:GenMalicious-BEM [Trj]
TencentMalware.Win32.Gencirc.10b1f774
Ad-AwareTrojan.Downloader.JRGI
SophosML/PE-A + Troj/Weelsof-JV
ComodoTrojWare.Win32.Kuluoz.DES@5iailn
VIPRETrojan.Downloader.JRGI
TrendMicroBKDR_KULUOZ.SM23
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Downloader.JRGI (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aztyt
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.60B
MicrosoftTrojanDownloader:Win32/Kuluoz
ViRobotTrojan.Win32.Agent.149504.Z
GDataTrojan.Downloader.JRGI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kuluoz.R127321
VBA32Worm.Aspxor
ALYacTrojan.Downloader.JRGI
MalwarebytesMalware.AI.481831498
RisingDownloader.Zortob!8.896 (TFE:5:vkcElHxRToO)
YandexWorm.Aspxor!vtycR0idjDg
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Weelsof.JV!tr
AVGWin32:GenMalicious-BEM [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.481831498?

Malware.AI.481831498 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment