Malware

Malware.AI.54062672 (file analysis)

Malware Removal

The Malware.AI.54062672 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.54062672 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys

How to determine Malware.AI.54062672?


File Info:

name: ACA96746DAC174A3B85D.mlw
path: /opt/CAPEv2/storage/binaries/eda831c523b80d36824293d864a68bcf5eaa33685d824bac9e6f4b145107d755
crc32: 27332AF6
md5: aca96746dac174a3b85d5ba4ec00e855
sha1: 8738f06d016ece0215b86fcd699667abad3a8876
sha256: eda831c523b80d36824293d864a68bcf5eaa33685d824bac9e6f4b145107d755
sha512: b2995dfef7f32934e2de121f78254f6f85f98ea63212cc7c10c2301a542d4b2c5b133e3a749aabf4bb04dd1c70aacd7bb5e07c9c6be91692d0e41625d42d25f5
ssdeep: 393216:3sAD35b69E8Hehq+0JF5asLwvuX647eLO:cy35u9E8H9F5djXj7eLO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FF633063396C026FFAB92336B56B742A6BD29654533893F13D80E79B8702B1173D763
sha3_384: 7940e3468652d274f0bf709c6a0e85dc75786ab77cf81fed80227b1439e1ae86bbf281396e00675882c391c2c8cdd15c
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-23 09:27:29

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.54062672 also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.AIT.Miner.A.B0557361
FireEyeGeneric.mg.aca96746dac174a3
CAT-QuickHealTrojan.AutoIt.MineDropper.C
ALYacGeneric.AIT.Miner.A.B0557361
CylanceUnsafe
K7AntiVirusTrojan ( 005411551 )
AlibabaTrojanDropper:AutoIt/Nymeria.df611eca
K7GWTrojan ( 005411551 )
Cybereasonmalicious.6dac17
BitDefenderThetaAI:Packer.BC75735117
CyrenW32/AutoIt.VP.gen!Eldorado
SymantecPUA.AutoItDropper
ESET-NOD32a variant of Win32/TrojanDropper.Autoit.TL
TrendMicro-HouseCallTROJ_GEN.R002C0DLV21
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGeneric.AIT.Miner.A.B0557361
AvastBV:CoinHelper-B [Miner]
Ad-AwareGeneric.AIT.Miner.A.B0557361
EmsisoftGeneric.AIT.Miner.A.B0557361 (B)
TrendMicroTROJ_GEN.R002C0DLV21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Autoit
GDataWin32.Trojan.BSE.196N20V
AviraDR/AutoIt.Gen
GridinsoftRansom.Win32.Miner.sa
ArcabitGeneric.AIT.Miner.A.BD88131
MicrosoftTrojanDropper:AutoIt/Nymeria.AR!MTB
CynetMalicious (score: 99)
AhnLab-V3Dropper/AU3.Miner.S1098
McAfeeArtemis!ACA96746DAC1
MAXmalware (ai score=80)
VBA32Trojan.Autoit.Wirus
MalwarebytesMalware.AI.54062672
APEXMalicious
RisingTrojan.CoinMiner/Autoit!1.C937 (CLASSIC)
eGambitGeneric.Malware
FortinetAutoIt/CoinMiner.TL!tr
AVGBV:CoinHelper-B [Miner]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.54062672?

Malware.AI.54062672 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment