Malware

About “Malware.AI.932124826” infection

Malware Removal

The Malware.AI.932124826 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.932124826 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Malware.AI.932124826?


File Info:

name: 81534E26D930B8ABC051.mlw
path: /opt/CAPEv2/storage/binaries/06d55bc20da49e24eed4dbc9e7a9e6797cbd15ffd965d6ab421a37b06b4094ef
crc32: D24C3E60
md5: 81534e26d930b8abc05188c1e3ef6258
sha1: 0ac3c4156b46534f633e8dce388bedaf859abb4e
sha256: 06d55bc20da49e24eed4dbc9e7a9e6797cbd15ffd965d6ab421a37b06b4094ef
sha512: c1fddd2295c4503f5f4ef006cc14933c23313e1d65c412ad51528d0df0806be4b96cc3599e9be6b36f7d9e94896e04b48422a0e842a031f5a0298894b1c2198b
ssdeep: 49152:3W6m4ZNJwpudaeIxDt2c0J7RiC4PafPfEwp0NCFdy:3WSuX9t0HiNvwp0NCy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1768523B08546857DCA7D30B6C82383CE7FD479987520AE227DCC733A9D6D5B280A257D
sha3_384: e637af3b2ecfa5221eaf1e5e829418b2da3c4341c7eb3ea80c7c12475738e9c488cbed17afb5b791fcb6bbb5b871df22
ep_bytes: 558becb9c30000006a00e2fc57565355
timestamp: 2009-03-05 20:57:33

Version Info:

CompanyName:
FileDescription: EVA Universal Binary
FileVersion: 8.0
InternalName: install
LegalCopyright:
ProductName: EVA Universal Binary
ProductVersion: 8.0
Translation: 0x0419 0x04e3

Malware.AI.932124826 also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.81534e26d930b8ab
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f05b1 )
K7GWTrojan ( 0040f05b1 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/FakeAlert.PC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Archsms-9867702-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Kryptik.dcgtkw
ComodoTrojWare.Win32.Kryptik.AXPG@4wu4cl
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Ransom
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.ArchSMS.G
McAfeePUP-XAQ-IL
VBA32SScope.Trojan.AET.5307
MalwarebytesMalware.AI.932124826
PandaTrj/Pacrypt.F
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.AOGD!tr
AVGWin32:Kryptik-OCR [Trj]
Cybereasonmalicious.56b465
AvastWin32:Kryptik-OCR [Trj]

How to remove Malware.AI.932124826?

Malware.AI.932124826 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment