Malware

What is “Malware.AI.578207873”?

Malware Removal

The Malware.AI.578207873 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.578207873 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.578207873?


File Info:

name: 9C39D6F52E1E1BE5AE61.mlw
path: /opt/CAPEv2/storage/binaries/f6160f1a9d13f2d49e9edc0136f53e0a9a9c06fe990cdd47a07837711c86e7e3
crc32: 561631DA
md5: 9c39d6f52e1e1be5ae61bab90971d054
sha1: dd75283b6a0507bab2ab1bcb7f21810350932a48
sha256: f6160f1a9d13f2d49e9edc0136f53e0a9a9c06fe990cdd47a07837711c86e7e3
sha512: e9764e4e61f447bee9c82d2eb0e27bc3d3902a9af816c4c8e32e64689befe7544a98daee2ee77911a000076ff7f2733b09ba4e35aa92788139aefda3bff05e9c
ssdeep: 196608:TcF4tUkvKka/wx0RRZYnePy/o2adWJwm2MOduCnzOlhYX6LCBe7u7d:TE4GkSfq0RReYyw2MdmbCn42qz0d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8B6338173A5033DD9ABB2F908240111DF39BF675AA41D0A53F23B5DB6710E7CE6A82D
sha3_384: e76ef78bfcf9cb4340cca8a5b551714c98a10f87f3e5cd29f7435748453d1585b9a5ad33b991b2bcbe9af79e8305326d
ep_bytes: e8e3feffff33c050505050e8f22d0000
timestamp: 2011-12-15 06:38:30

Version Info:

CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 3.71
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2007
OriginalFilename: WinRAR.exe

Malware.AI.578207873 also known as:

LionicTrojan.Win32.Xtrat.4!c
Elasticmalicious (moderate confidence)
FireEyeTrojan.Uztuby.21
McAfeeArtemis!9C39D6F52E1E
CylanceUnsafe
SangforTrojan.Win32.Kazy.frHu
BitDefenderTrojan.Uztuby.21
Cybereasonmalicious.52e1e1
SymantecTrojan.Dropper
ESET-NOD32Win32/Spy.Delf.NYS
TrendMicro-HouseCallBKDR_XTRAT.LTY
Paloaltogeneric.ml
ClamAVWin.Packed.Bladabindi-7194433-0
KasperskyTrojan.Win32.Llac.lrrt
AlibabaTrojanSpy:Win32/TScope.19afbc33
NANO-AntivirusTrojan.Win32.Agent.crhqro
ViRobotTrojan.Win32.Z.Xtrat.10472200
RisingSpyware.Delf!8.12D (KTSE)
SophosMal/Generic-S
ComodoMalware@#2sf2c36vihzc6
DrWebTrojan.PWS.Multi.2332
VIPRETrojan.Uztuby.21
TrendMicroBKDR_XTRAT.LTY
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Uztuby.21 (B)
WebrootW32.Backdoor.Gen
AviraTR/Spy.Agent.hpdup
Antiy-AVLTrojan/Generic.ASMalwS.3C54
MicrosoftTrojan:MSIL/Cryptor
GDataGen:Variant.Razy.778916
AhnLab-V3Win-Trojan/Xtrat.10472200
VBA32Trojan.Wacatac
ALYacGen:Variant.Razy.778916
MAXmalware (ai score=100)
MalwarebytesMalware.AI.578207873
TencentWin32.Trojan.Falsesign.Hufp
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/XTRAT.LTY!tr.bdr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.578207873?

Malware.AI.578207873 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment