Malware

About “Malware.AI.700680713” infection

Malware Removal

The Malware.AI.700680713 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.700680713 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Binary compilation timestomping detected

Related domains:

wpad.local-net

How to determine Malware.AI.700680713?


File Info:

name: C2AAB3EDF287B5CA0F9B.mlw
path: /opt/CAPEv2/storage/binaries/76424d9e4d44e5bbfb874718386e6d3c0254970737b0b09708b5e1230969bf2f
crc32: EF87C6E3
md5: c2aab3edf287b5ca0f9bd9bda5d0b7d2
sha1: b4641965357d83f21fdab062f4492bb1b6aab297
sha256: 76424d9e4d44e5bbfb874718386e6d3c0254970737b0b09708b5e1230969bf2f
sha512: ba7f507afc052381f1c4d674474121172e2b3a7c131ee5a45b9d540dd0d2ab9f04cedd47cfe8efa5fa0c6b6cead466906622f4dd7d650573181fc4e1afa7cabb
ssdeep: 24576:C+hMCjD+ZVe877NDBhyxhATByEUA2I7fgCl3xKU7P/OO7Z:C+hXmZVe8HRy/A1/x7fgCnKcDt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A15226B7448CA28C596433EC8D991F05B31BC52DF42CE37BD89BF9F32399C26661A05
sha3_384: 2df5d644e662907aeea9721845312fbd5c9c80fd1239aa4e3660f1cfc3a47438af2f76c2c6ecfa6ccdd6e81b1de127f6
ep_bytes: ff250020400000000000000000000000
timestamp: 2052-01-12 13:38:28

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: funnyvirus
FileVersion: 1.0.0.0
InternalName: funnyvirus.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: funnyvirus.exe
ProductName: funnyvirus
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.700680713 also known as:

MicroWorld-eScanGen:Heur.Bodegun.1
FireEyeGeneric.mg.c2aab3edf287b5ca
CylanceUnsafe
K7AntiVirusTrojan ( 005828291 )
K7GWTrojan ( 005828291 )
Cybereasonmalicious.df287b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/BadJoke.ZD
APEXMalicious
BitDefenderGen:Heur.Bodegun.1
AvastWin32:Trojan-gen
Ad-AwareGen:Heur.Bodegun.1
ZillyaTool.ZD.Win32.1
EmsisoftGen:Heur.Bodegun.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Bodegun.1
AviraTR/BadJoke.lqmhr
Antiy-AVLTrojan/Generic.ASMalwS.34A3186
ArcabitTrojan.Bodegun.1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4637790
BitDefenderThetaGen:NN.ZemsilF.34294.5m1@aCDsN7k
MAXmalware (ai score=81)
MalwarebytesMalware.AI.700680713
YandexTrojan.BadJoke!FS1+AVh8PAc
IkarusTrojan.MSIL.BadJoke
AVGWin32:Trojan-gen

How to remove Malware.AI.700680713?

Malware.AI.700680713 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment