Malware

About “Malware.AI.735857454” infection

Malware Removal

The Malware.AI.735857454 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.735857454 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Modifies or disables Windows SmartScreen
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Created a service that was not started
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.735857454?


File Info:

name: 24B60486B4EA7356E613.mlw
path: /opt/CAPEv2/storage/binaries/0c70787355ce3c2d83b69ef28b8423dc7cb3b7d1dc70df4bb364c1fa9a77203a
crc32: 564379D6
md5: 24b60486b4ea7356e613971c39555ea9
sha1: cd82ef2f0c44958ead447fb10ba284334fec1627
sha256: 0c70787355ce3c2d83b69ef28b8423dc7cb3b7d1dc70df4bb364c1fa9a77203a
sha512: c05e89af27805210441de7a72864dc487eb78f41a1dabeaf348a283609a06ba8c99acc243d428a1eae336ff3038b5f9f7d584e70bf3538f41a3a9c8beb571dea
ssdeep: 49152:FRwyoKDaEggVVbpG+APDR0fCSeQ2t7IHhehV3Iqjy9YoMe3h/oBArCLA6PYe:FaKawGnPtyCSz+kIYqjy9Y+h6ArCLA6L
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169D5331576893113FA5309746BBBBB4463ADB2C059CD458937CCBF28238B1CADF4E61A
sha3_384: e14260b28030172262ac0a432937bb78c0ad55fd1ac80f5c967c7224fa8ba26801bb84f7841cfd9750ad314728231776
ep_bytes: 558bec81ec80010000535633db57895d
timestamp: 2007-03-31 15:09:55

Version Info:

0: [No Data]

Malware.AI.735857454 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Hacktool.KMSActivator.14
FireEyeGeneric.mg.24b60486b4ea7356
CAT-QuickHealScript.Trojan.45893
McAfeeCrack-KMS
CylanceUnsafe
K7GWUnwanted-Program ( 004d38111 )
K7AntiVirusUnwanted-Program ( 004d38111 )
BaiduMulti.Threats.InArchive
CyrenW32/S-dcf8c7bd!Eldorado
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.VBS.Agent.xt
BitDefenderGen:Variant.Application.Hacktool.KMSActivator.14
NANO-AntivirusRiskware.Win32.ProcPatcher.dwvwln
AvastWin32:PUP-gen [PUP]
Ad-AwareVBS.Heur.Worm.Dunihi.4.A1F2F5BC.Gen
ComodoMalware@#3sxbbyxlkcmfp
DrWebTrojan.Moneyinst.709
VIPREGen:Variant.Application.Hacktool.KMSActivator.14
TrendMicroPUA.MSIL.AutoKMS.I
EmsisoftApplication.HackTool (A)
IkarusHackTool.Win32.AutoKMS
GDataBAT.Trojan.Agent.TPLV1J
JiangminRiskTool.ProcPatcher.uh
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASSuf.2370B
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
BitDefenderThetaGen:NN.ZemsilF.34592.cn1@a4sZl0o
ALYacVBS.Heur.Worm.Dunihi.4.A1F2F5BC.Gen
MAXmalware (ai score=89)
VBA32Trojan.Moneyinst
MalwarebytesMalware.AI.735857454
TrendMicro-HouseCallPUA.MSIL.AutoKMS.I
RisingTrojan.Kryptik/VBS!1.A240 (CLASSIC:IYUhqaJin+ZZeZqhKbCBFQ)
SentinelOneStatic AI – Malicious PE
FortinetRiskware/IdleKMS
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.6b4ea7

How to remove Malware.AI.735857454?

Malware.AI.735857454 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment