Malware

Malware.AI.1284542985 malicious file

Malware Removal

The Malware.AI.1284542985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1284542985 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings

How to determine Malware.AI.1284542985?


File Info:

name: 8DCBDF3E996912673570.mlw
path: /opt/CAPEv2/storage/binaries/c3b4a97abeed33008572d3259171b9b18b00ab0320af703fdebb188c7902e1c1
crc32: 7FF7B790
md5: 8dcbdf3e9969126735708714ac6e7254
sha1: 672998333491234013480b8a2072cf9087611576
sha256: c3b4a97abeed33008572d3259171b9b18b00ab0320af703fdebb188c7902e1c1
sha512: 516c40e93ddce81563cb4f4a1b2f3f804956e405f10e90beb43507f16cdea6957d414e91058b400845c35070818c09ba5d740dd724dffb6de85e60a4c46bbb7f
ssdeep: 12288:qK2mhAMJ/cPlA2KHjllE34rZhaVv8zHzlj4tB2gkl38Iq:b2O/GlA3E3INpL8Iq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDC408D1E384D59ED41B0276CC7AE9719517AEAE8474850E252E3D2B36F7383206BE0F
sha3_384: e05265c6496d53b2507bde02aef8aac09c4eac0eac1b6415d334e151a6e5683f07c2044e8b76e6d22835f8b785a33cd1
ep_bytes: e8e3feffff33c050505050e89f300000
timestamp: 2012-06-09 13:19:49

Version Info:

0: [No Data]

Malware.AI.1284542985 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Downloader.133181-1
FireEyeGeneric.mg.8dcbdf3e99691267
McAfeeArtemis!2106252A76F6
MalwarebytesMalware.AI.1284542985
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
Cybereasonmalicious.e99691
ESET-NOD32a variant of Win32/Agent.QFY
CynetMalicious (score: 99)
KasperskyTrojan-Downloader.Win32.Agent.xtjh
BitDefenderGen:Variant.Johnnie.327558
NANO-AntivirusTrojan.Win32.Agent.bjcdmq
MicroWorld-eScanGen:Variant.Johnnie.327558
RisingDownloader.Agent!8.B23 (CLOUD)
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.TEN@4pfqba
DrWebDLOADER.Trojan
VIPREGen:Variant.Johnnie.327558
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Johnnie.327558 (B)
SentinelOneStatic AI – Malicious SFX
AviraHEUR/AGEN.1242645
Antiy-AVLTrojan/Generic.ASMalwS.13
KingsoftWin32.TrojDownloader.Agent.xt.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Downloader.Win32.Agent.xtjh
GDataGen:Variant.Johnnie.327558
GoogleDetected
VBA32BScope.Adware.Kraddare
ALYacGen:Variant.Johnnie.327558
MAXmalware (ai score=83)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.XTJH!tr.dldr
BitDefenderThetaAI:Packer.C2E681EB20
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Malware.AI.1284542985?

Malware.AI.1284542985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment