Malware

What is “Malware.AI.861974050”?

Malware Removal

The Malware.AI.861974050 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.861974050 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Malware.AI.861974050?


File Info:

crc32: D98DE6C5
md5: b78fc9ecf15f7ad93399f3feb4a26a15
name: B78FC9ECF15F7AD93399F3FEB4A26A15.mlw
sha1: 1eaa9578f4172e64c8945b687a04db4861c28d9f
sha256: 9c637da6f0562443d5e7b01eafa9cb8d013812c336a59258f0d6ab8e1f08612b
sha512: 5ca85e77806908ea4401293b44aa39d7779c913bb0149bb7f36f65b0ec62fe60250834b485f168ef1ed8abc46fd268d908271e36af123ea03ee355068acbd042
ssdeep: 3072:aTsn0RddSKViik3x+3LOslPzgiB4jRSBR5bL8rdi8/AlkKa0zkA7+RaUEInnirT:aTcKVzy+bzbg6RbSdRAlkKcAXUEX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Design Science, Inc. 1990-2013
InternalName: Design Science situp Utility
FileVersion: 2013.2.5.0
CompanyName: D esign Science, Inc.
LegalTrademarks: Design Science situp Utility is a trademark of Design Science, Inc.
ProductName: Design Science situp Utility
ProductVersion: 6.9 (13020500)
FileDescription: De sign Science situp Utility
OriginalFilename: situp.EXE
Translation: 0x0409 0x04e4

Malware.AI.861974050 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
CAT-QuickHealRansom.Cerber.G4
McAfeeRansomware-GCQ!B78FC9ECF15F
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforRansom.Win32.Cerber_102.se
K7AntiVirusTrojan ( 005224381 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 004f32e21 )
Cybereasonmalicious.cf15f7
BitDefenderThetaGen:NN.ZexaF.34590.Mq0@aea6rzmi
CyrenW32/S-e3cc8b89!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FAXJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.0d39c38a
NANO-AntivirusTrojan.Win32.Encoder.evqxqz
RisingTrojan.Kryptik!1.AF0E (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Encoder.4691
TrendMicroRansom_CERBER.SMFE
McAfee-GW-EditionRansomware-GCQ!B78FC9ECF15F
FireEyeGeneric.mg.b78fc9ecf15f7ad9
SophosML/PE-A + Mal/Cerber-AK
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.Generic.cdkbt
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
VBA32BScope.TrojanRansom.Shade
ALYacTrojan.Ransom.Cerber.1
MAXmalware (ai score=100)
MalwarebytesMalware.AI.861974050
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CERBER.SMFE
TencentWin32.Trojan.Generic.Pgdb
YandexTrojan.Agent!aoLxdbunmeQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.HJJV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Cerber.HgIASOUA

How to remove Malware.AI.861974050?

Malware.AI.861974050 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment