Malware

Malware.AI.963211709 (file analysis)

Malware Removal

The Malware.AI.963211709 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.963211709 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file

How to determine Malware.AI.963211709?


File Info:

name: F0AB1EDBC3C443FF8E00.mlw
path: /opt/CAPEv2/storage/binaries/1a71e6dd51f200ec4e315cc6193071081e722f660caa325645a6421bf59af44b
crc32: AE392498
md5: f0ab1edbc3c443ff8e008f50c5721536
sha1: bab1339592c2ff394e5a937ad2a43138ab2326c7
sha256: 1a71e6dd51f200ec4e315cc6193071081e722f660caa325645a6421bf59af44b
sha512: 196ce6486d77b97d8106f83d8d942773c92ed2e46c545a05b6604bfa2938e13acc7633b74794f1e577ad519aeec51510b422ecdcf49b057ee06bb28cb125c6aa
ssdeep: 12288:cNeaqrk9zAe0+ChW/4nKMYf/ZWvaMgcqYzJ:pe98nUHUMcq8
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D0A4124DC8874EBAE8F53C307AA4A1FD95557287EF8050E1CED6CE70C8357DA899321A
sha3_384: f2e1273d7c2e59dc4deef2ad501fa88b57f948c4dd3053cbdfe7bfaccaea95cedf9d5987440639e1f8c8acdcac680980
ep_bytes: 60be003042008dbe00e0fdff57eb0b90
timestamp: 2016-05-10 22:18:20

Version Info:

CompanyName: Masquerade
FileDescription: Verify MSQ archives
FileVersion: 0. 0. 0. 0
InternalName: Verify.Tool
LegalCopyright: Masquerade // MASQUERADE.SITE
LegalTrademarks:
OriginalFilename: Verify.exe
ProductName: Verify Tool
ProductVersion: 0. 0. 0. 0
Comments: Verify MSQ archives
Translation: 0x0409 0x04e4

Malware.AI.963211709 also known as:

LionicTrojan.Win32.Zbot.lAby
MicroWorld-eScanTrojan.GenericKD.36051459
FireEyeGeneric.mg.f0ab1edbc3c443ff
McAfeeGenericRXAA-AA!F0AB1EDBC3C4
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.6728
SangforTrojan.Win32.Ymacco.AA1A
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H06KQ21
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9869321-0
BitDefenderTrojan.GenericKD.36051459
SUPERAntiSpywareTrojan.Agent/GenericKD
EmsisoftTrojan.GenericKD.36051459 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.gc
SophosMal/Generic-S
JiangminClient-SMTP.Blat.ag
WebrootPua.Hacktool
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.19D651B
MicrosoftTrojan:Win32/Ymacco.AA1A
ViRobotTrojan.Win32.Z.Agent.453328
GDataTrojan.GenericKD.36051459
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R356489
VBA32Trojan.MSIL.Agent
ALYacTrojan.GenericKD.36051459
MalwarebytesMalware.AI.963211709
APEXMalicious
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
YandexTrojan.GenAsa!fHFEUiatRPg
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
Cybereasonmalicious.bc3c44
PandaGeneric Suspicious

How to remove Malware.AI.963211709?

Malware.AI.963211709 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment