Malware

Malware.AI.83036731 information

Malware Removal

The Malware.AI.83036731 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.83036731 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Suspicious wmic.exe use was detected

How to determine Malware.AI.83036731?


File Info:

name: 1EBB0E2DB69BD7F9263D.mlw
path: /opt/CAPEv2/storage/binaries/21042b2e1c9c9ff35349c366a7e1cc800a4f3b4d69c70c015d744fb5c1d4d8a6
crc32: A3553E18
md5: 1ebb0e2db69bd7f9263d3f24ce30a655
sha1: 0d4eb45cbab54aa01268c7925ccb19e34892e8ec
sha256: 21042b2e1c9c9ff35349c366a7e1cc800a4f3b4d69c70c015d744fb5c1d4d8a6
sha512: ae79cb5f55a96b4108312bcb3b669c9133f198f5c8f774927274fd767dff885b45b23bd16b980804a95f187d603820513dab342c2e02a2aa525a24d8eb91cf0d
ssdeep: 24576:NRRnFIdCDOz/qIk2GqxEzzCPuwRTugxxa9AOJBV1Ls2wBP:NRdFIdCDO5CwTtxxa9PJBV1Ls2wB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8359D83B6C950FAE7D211B244667636E9316B1D03A5CED397CC29BD9821FD1BE38384
sha3_384: f49d9fd43d7c89d5345288ead5ca2a7a094c9fbb34982aacdafc724d793c21d3e743e017d2a539ed22eab5a33a64c75e
ep_bytes: 68080c00006800000000682ceb4f00e8
timestamp: 2017-08-23 03:01:29

Version Info:

CompanyName: Cheathappens
ProductName: Kingsway
ProductVersion: 55777
FileVersion: 1.0001
InternalName: 1.1.4
Translation: 0x0000 0x04b0

Malware.AI.83036731 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.l!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.1ebb0e2db69bd7f9
McAfeeArtemis!1EBB0E2DB69B
CylanceUnsafe
ZillyaTrojan.Convagent.Win32.4332
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Ulise.b6a3cf67
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/S-bff053f5!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.FYVKAVL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Gamehack-6847638-0
KasperskyVHO:Trojan-Spy.Win32.Convagent.gen
BitDefenderTrojan.GenericKD.38167681
MicroWorld-eScanTrojan.GenericKD.38167681
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11490f71
Ad-AwareTrojan.GenericKD.38167681
EmsisoftTrojan.GenericKD.38167681 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GL621
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosCheathappens (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.EVJ1OU
AviraTR/Agent.vkauc
Antiy-AVLTrojan/Generic.ASMalwS.2A4A3B6
ArcabitTrojan.Generic.D2466481
MicrosoftPWS:Win32/Zbot!ml
AhnLab-V3Malware/Win32.RL_Generic.R286658
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34062.dv0@a8imDIei
ALYacTrojan.GenericKD.38167681
MAXmalware (ai score=82)
VBA32TrojanSpy.Convagent
MalwarebytesMalware.AI.83036731
TrendMicro-HouseCallTROJ_GEN.R002C0GL621
RisingPUF.GameHack!1.B348 (CLASSIC)
YandexTrojan.GenAsa!WYcMuCUDuY0
IkarusTrojan.Ulise
eGambitUnsafe.AI_Score_99%
FortinetW32/Ulise.5704!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Malware.AI.83036731?

Malware.AI.83036731 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment