Malware

Malware.AI.1027859928 (file analysis)

Malware Removal

The Malware.AI.1027859928 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1027859928 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1027859928?


File Info:

name: 3454502856913681BE07.mlw
path: /opt/CAPEv2/storage/binaries/3fcdb80115ec7bd1fedc28208b0b74c544f258998d68ca3100cece10aff80036
crc32: B6D48DC3
md5: 3454502856913681be07719d09ecaff8
sha1: c1b45bcf915155758accd710e3640de4723616d9
sha256: 3fcdb80115ec7bd1fedc28208b0b74c544f258998d68ca3100cece10aff80036
sha512: 8c09bfb1b0657c22d1120332cfc421921da9efae239ec0061c25d5f485f4f57c4269b6f95b94ba3671b0bae84a082097d78b1cf22810238d7b0071e86673aefe
ssdeep: 49152:X6KOelzvlI7uK2UwY0/KcnTUXN8hGuYeVAfF2C26XkYRW4abu7/TaVirsdp:X6KOMvlIKKcYLAw26Xl8ujTa8rsdp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C858E2277618077C56316308E1EF229B2B9FA700E3946B763D45F2D2FB019399396B7
sha3_384: 3c34ca0745ee41b359b4b10a9ab7a60a037348f618fb33aaea14947a383b3dafe065ff68f99c8e2b58c079837a4d686d
ep_bytes: e8110a0000e980feffff8b4df464890d
timestamp: 2016-11-21 14:37:32

Version Info:

CompanyName: Orange Legal Technologies Forest
ProductVersion: 8.5.69.33
ProductName: Addanswer
LegalCopyright: Copyright © 2001 Orange Legal Technologies Forest. All rights reserved
FileDescription: Addanswer
OriginalFilename: bitside.exe
InternalName: Addanswer
Translation: 0x0409 0x04b0

Malware.AI.1027859928 also known as:

LionicTrojan.Win32.Ursnif.tpCd
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.28481
MicroWorld-eScanTrojan.Agent.DJQZ
FireEyeGeneric.mg.3454502856913681
CAT-QuickHealTrojan.Tiggre.S4410650
McAfeePacked-FOP!345450285691
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1022076
SangforTrojan.Win32.Agent.gen
K7AntiVirusSpyware ( 00538dab1 )
AlibabaTrojanSpy:Win32/Ursnif.c42e65b9
K7GWSpyware ( 00538dab1 )
Cybereasonmalicious.856913
BitDefenderThetaGen:NN.ZexaF.34114.Vz0@aOT4hEji
VirITTrojan.Win32.Banker1.BQDL
CyrenW32/S-4733b24d!Eldorado
SymantecInfostealer
ESET-NOD32Win32/Spy.Ursnif.BW
TrendMicro-HouseCallTROJ_GEN.R002C0DA222
Paloaltogeneric.ml
ClamAVWin.File.Sodinokibi-9779217-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DJQZ
NANO-AntivirusTrojan.Win32.Ursnif.fkpitl
SUPERAntiSpywareTrojan.Agent/Gen-Ursnif
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b235ac
Ad-AwareTrojan.Agent.DJQZ
TACHYONTrojan-Spy/W32.Ursnif.1829376
EmsisoftTrojan-Spy.Ursnif (A)
ComodoTrojWare.Win32.Tiggre.BW@7y3xhc
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DA222
McAfee-GW-EditionPacked-FOP!345450285691
SophosMal/Generic-S
GDataTrojan.Agent.DJQZ
JiangminTrojanSpy.Ursnif.buw
AviraTR/AD.Ursnif.xmaww
Antiy-AVLTrojan/Generic.ASMalwS.2990972
GridinsoftRansom.Win32.Sodinokibi.sa
ViRobotTrojan.Win32.Z.Ursnif.1829376.GQ
MicrosoftTrojanSpy:Win32/Ursnif.IG!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ursnif.R245884
Acronissuspicious
VBA32TrojanPSW.Banker
ALYacTrojan.Agent.DJQZ
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1027859928
APEXMalicious
RisingSpyware.Ursnif!8.1DEF (CLOUD)
YandexTrojan.GenAsa!CZS0bihdKEQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Ursnif.BW!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1027859928?

Malware.AI.1027859928 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment