Malware

Malware.AI.913906047 malicious file

Malware Removal

The Malware.AI.913906047 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.913906047 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Malware.AI.913906047?


File Info:

name: BA18C40A2091246748A7.mlw
path: /opt/CAPEv2/storage/binaries/b5130fdf0dc054d6943757b688090d7023cb48a409c199b80eb7d0f2530fbf59
crc32: 97DE09F2
md5: ba18c40a2091246748a79f145ecdddad
sha1: ce407009115b2b7bd72c561534a563b55b7d5b2e
sha256: b5130fdf0dc054d6943757b688090d7023cb48a409c199b80eb7d0f2530fbf59
sha512: 982f6d57ffe08fcdb595fc7c1a786f1f43c7b5d7bc94dfb5800559f88e5a452558b9a4ab5acd64543360ca6b4bd234d1d1302db8437fd9ffea6ef76926ebaa66
ssdeep: 98304:rHoMTmRGVOLzRlaV+5m4rBNJwTZfn9JLaGeK0K6vr43E:70UGRMVcmCPJwtn9JLzeXKh0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C460255F0587C95C40364F45C3EEAB4102ABF6A1A3C89057A7FFA2F9A7A6C23051F4E
sha3_384: 376b31dfca0bee3743c260e3e6fa6ed6f21cdf2b141ceaf5b4e63159242f93abee9f97e9caf44de106f3dcddf625c55d
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Malware.AI.913906047 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ba18c40a20912467
McAfeeArtemis!BA18C40A2091
CylanceUnsafe
AlibabaTrojan:Win32/Generic.9b4b92b1
Cybereasonmalicious.a20912
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Dorifel-9910700-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGeneric.Starter.5.A4DD6168
MicroWorld-eScanGeneric.Starter.5.A4DD6168
Ad-AwareGeneric.Starter.5.A4DD6168
SophosMal/Generic-S
DrWebTrojan.Siggen16.26900
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGeneric.Starter.5.A4DD6168 (B)
Paloaltogeneric.ml
GDataGeneric.Starter.5.A4DD6168
GridinsoftRansom.Win32.Sabsik.sa
ArcabitGeneric.Starter.5.A4DD6168
MicrosoftPUA:Win32/CoinMiner
ALYacGeneric.Starter.5.A4DD6168
MAXmalware (ai score=85)
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.913906047
TrendMicro-HouseCallTROJ_GEN.R002H07A622
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Malware.AI.913906047?

Malware.AI.913906047 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment