Malware

What is “Malware.AI.1311963887”?

Malware Removal

The Malware.AI.1311963887 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1311963887 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1311963887?


File Info:

name: FC93B362844906E7A5C2.mlw
path: /opt/CAPEv2/storage/binaries/8e2161babde07d1ac1b3ba862d3121a4a048936d472029a8cdc22921e2153dd5
crc32: 67B9747C
md5: fc93b362844906e7a5c2bc3183a34877
sha1: 7611854055ad1ba8149c08a11e1eb560ebcee268
sha256: 8e2161babde07d1ac1b3ba862d3121a4a048936d472029a8cdc22921e2153dd5
sha512: ceabb733a9dfe3a866861d6c0eff06a6e69457cb1055ef7ac1e02d695fc8407a23f459588ea983d7ea991ee7a6e9b0d655656590c3c5f69596c313eeb6900aa3
ssdeep: 12288:+Mroy90okGg/Rfxl66KVTwvWAEe6tZPh63:CyaGgpfD6lKvyeo+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14DB40252BAD89073EEB5277418F602830737BCA19D38432B27516A5A1DB3AD0F53637B
sha3_384: 15bebd5919bd46f08ba2e09eaad07d0d90c24e56aa1e3bec64d3735145f2446ad5e892a3f65360420c9019df73027d47
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0409 0x04b0

Malware.AI.1311963887 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Crifi.1
FireEyeGen:Heur.Crifi.1
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00536d121 )
K7GWTrojan ( 005690671 )
Cybereasonmalicious.055ad1
ArcabitTrojan.Crifi.1
VirITTrojan.Win32.Genus.RPR
CyrenW32/Kryptik.JKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
ClamAVWin.Packed.Lazy-9958163-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Heur.Crifi.1
NANO-AntivirusTrojan.Win32.SmokeLoader.jxaglw
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Heur.Crifi.1 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Siggen19.32857
VIPREGen:Heur.Crifi.1
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminesuspicious.low.ml.score
SophosTroj/PlugX-EC
IkarusTrojan.Spy.Stealer
JiangminBackdoor.Mokes.hou
GoogleDetected
AviraTR/Spy.RedLine.lbwpe
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.SmokeLoader
MicrosoftTrojan:Script/Phonzy.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataWin32.Trojan.PSE.9TLXQ0
CynetMalicious (score: 99)
Acronissuspicious
MalwarebytesMalware.AI.1311963887
APEXMalicious
RisingBackdoor.Mokes!8.619 (TFE:4:7n4IsIjnBDK)
SentinelOneStatic AI – Malicious SFX
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.1311963887?

Malware.AI.1311963887 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment