Malware

Malware.AI.519592961 removal tips

Malware Removal

The Malware.AI.519592961 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.519592961 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.519592961?


File Info:

name: A0B596C90DA323D06ED1.mlw
path: /opt/CAPEv2/storage/binaries/0233a0680566a39f30e9cea2d8de9dafc2b26d22dd551f7404dd3d407731bc7b
crc32: B245E7C7
md5: a0b596c90da323d06ed1240bed3affd8
sha1: 28212c9ada1a62a2ff55745f392e50ff229251b6
sha256: 0233a0680566a39f30e9cea2d8de9dafc2b26d22dd551f7404dd3d407731bc7b
sha512: 3ddc7eee8e5ffc2a7d227fc37f5c3fbe3776d535c478110ba980027fe44b800b4e2cc8bcc0363ed6c2a5476754f5c9b862932325cddd4bee9ea212e543d7bc6d
ssdeep: 49152:GBbJcpqp3UMjFw/oW/10YsPRYkcGcOdEYksGcrdLvZYksGcrd:fP/fyYdkcGc6ksGcRvuksGc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18FA57C8B6361C893DBB143B5C894F335873476D46A6E87CB24F0689EFE92F925D22710
sha3_384: eb4cd4fc32febc4e848b773487c7d798af6d4ba74d0d4119db05898485fd0e7f5ebdb7b089c2b555adc269af50d48446
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-05 05:33:23

Version Info:

Translation: 0x0000 0x04b0
CompanyName: torpedo
FileDescription: cratercouncil
FileVersion: 6.28.90.2
InternalName: hearse.exe
LegalCopyright: smoke © think
OriginalFilename: hearse.exe
ProductName: behavior
ProductVersion: 6.28.90.2
Assembly Version: 6.28.90.2

Malware.AI.519592961 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Generic.TRFH5
ALYacGen:Variant.Razy.490172
CylanceUnsafe
VIPREBackdoor.MSIL.Bladabindi.a (v)
Cybereasonmalicious.90da32
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Kryptik.CRY.gen!Eldorado
SymantecScr.Malcode!gdn33
ESET-NOD32a variant of MSIL/Kryptik.PSV
APEXMalicious
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyTrojan.MSIL.Disfa.bqd
BitDefenderGen:Variant.Razy.490172
MicroWorld-eScanGen:Variant.Razy.490172
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
EmsisoftGen:Variant.Razy.490172 (B)
ComodoTrojWare.MSIL.Bladabindi.C@57iw6e
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.MulDrop6.47155
McAfee-GW-EditionPacked-PM!A0B596C90DA3
FireEyeGeneric.mg.a0b596c90da323d0
SophosTroj/DotNet-P
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen7
MAXmalware (ai score=89)
MicrosoftTrojan:MSIL/Remcos.PH!MTB
GDataGen:Variant.Razy.490172
McAfeePacked-PM!A0B596C90DA3
VBA32Trojan.MSIL.Disfa
MalwarebytesMalware.AI.519592961
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.DTL!tr
BitDefenderThetaGen:NN.ZemsilF.34182.@n0@aGc7Dqj
AVGMSIL:Agent-DRD [Trj]
AvastMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.519592961?

Malware.AI.519592961 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment