Malware

What is “Malware.AI.56705208”?

Malware Removal

The Malware.AI.56705208 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.56705208 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.56705208?


File Info:

name: 657B11B10C1D0AA90A15.mlw
path: /opt/CAPEv2/storage/binaries/db25a5d204244fb00523acaaa87edc0f0c73f60b8644d78e0e5219d309c9e357
crc32: 4EF567FE
md5: 657b11b10c1d0aa90a150cdfad75d0df
sha1: 680a820d63d2bd432d29f38ab062bbd79ff503a4
sha256: db25a5d204244fb00523acaaa87edc0f0c73f60b8644d78e0e5219d309c9e357
sha512: 51e9731612ad163acc575cf1c87ce39bb8794a416de8d46eaec113488fc30ac710efee799bb83ef6111140467fca463e0b2bc6819d2d5276e963a185efc832a8
ssdeep: 196608:tt7yi2OEOsOEONPGyi8yi2Odyi21OEO9OEOvyi21OEOCOEOsOEONPGyi8yi2Odyl:txlGybspGyb8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FA62327E1433076F26DCB7F5E9415A9140AEE32FF22940B3934CA1E86F67C76926607
sha3_384: f6c1fb1da9e2fe22a99b499ebee2152a5e9f6ec79f36b58c0ac5b0b515bfa6acbb75ce5510fd7389ac40215fd4121ed8
ep_bytes: 558bec83c4f0b8140b4600e80459faff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.56705208 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.HideProc.1!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.657b11b10c1d0aa9
McAfeeDownloader-BSI
CylanceUnsafe
ZillyaRootkit.Xanfpezes.Win32.13
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.10c1d0
ArcabitTrojan.Generic.D2205F49
CyrenW32/DelfInject.A.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32Win32/HideProc.O potentially unsafe
APEXMalicious
AvastWin32:HideProc-N [PUP]
ClamAVWin.Trojan.Hideproc-77
Kasperskynot-a-virus:RiskTool.Win32.HideProc.pe
BitDefenderTrojan.GenericKD.35675977
NANO-AntivirusRiskware.Win32.HideProc.crvalg
MicroWorld-eScanTrojan.GenericKD.35675977
TencentMalware.Win32.Gencirc.10b0d972
Ad-AwareTrojan.GenericKD.35675977
EmsisoftTrojan.GenericKD.35675977 (B)
DrWebTrojan.Fakealert.28173
VIPRERootkit.Win32.Xanfpezes.br (v)
TrendMicroRTKT_HIDEPROC.BB
McAfee-GW-EditionBehavesLike.Win32.Autorun.tc
SophosGeneric ML PUA (PUA)
Paloaltogeneric.ml
JiangminTrojanDropper.Delf.cdq
AviraTR/Rootkit.Gen
Antiy-AVLRiskWare[RiskTool]/Win32.HideProc
MicrosoftTrojanDownloader:Win32/Banload
GDataTrojan.GenericKD.35675977
TACHYONTrojan/W32.DP-Agent.10039382
AhnLab-V3Trojan/Win32.Banload.R242045
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34062.@RZ@aq1!wOmb
ALYacTrojan.GenericKD.35675977
MAXmalware (ai score=80)
VBA32TrojanDownloader.Banload
MalwarebytesMalware.AI.56705208
TrendMicro-HouseCallRTKT_HIDEPROC.BB
RisingRootKit.Win32.HideProc.l (CLASSIC)
YandexTrojan.GenAsa!BV58epBPBCU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.500016.susgen
FortinetRiskware/HideProc
AVGWin32:HideProc-N [PUP]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.56705208?

Malware.AI.56705208 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment