Malware

Malware.AI.1357877039 (file analysis)

Malware Removal

The Malware.AI.1357877039 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1357877039 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Malware.AI.1357877039?


File Info:

name: C2DD64EF32541B0C1688.mlw
path: /opt/CAPEv2/storage/binaries/e86964daf08b7d9928fc618f4096c96e46061af8b69df3aa54e50478fd57588b
crc32: 54A599A1
md5: c2dd64ef32541b0c1688c24929137e58
sha1: 9cf54beaac26145859f9f7ee8c4f8bb4ad42c1ac
sha256: e86964daf08b7d9928fc618f4096c96e46061af8b69df3aa54e50478fd57588b
sha512: f2b3e8d5cf2dc64ae14cae5b77b19f814c177d4fe83ef775b2f1b81988f2fc3f831b75591b6ec4253cd3e7e0a9dc20fde9c50d7048abcdb19f27f2900d5d1e71
ssdeep: 24576:lTbBv5rU3apzguphG1FT1qxQneIQIBsyhDOZ7dDXodVPYbS0Yaq7z35y+:PBZpzguphoFT1qfIQIBVFA1mVPMS0C3h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B551203BDC088B3D4A518326B56A720AA3CF6202F718EDFE7CB4ABDD9215D1D735691
sha3_384: 85d9e1148401df6bbf55bc122eb415286af514f4c732e54b72e6228c1472edb78a0df67bfea641dd2948b5ac18047277
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Malware.AI.1357877039 also known as:

BkavW32.Common.95009C18
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.68797940
ClamAVWin.Malware.Fugrafa-9938779-0
FireEyeGeneric.mg.c2dd64ef32541b0c
CAT-QuickHealTrojan.Agent
McAfeeArtemis!C2DD64EF3254
Cylanceunsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.aac261
ArcabitTrojan.Generic.D419C5F4
CyrenW64/Rozena.EL.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.68797940
SophosMal/Generic-S
VIPRETrojan.GenericKD.68797940
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.68797940 (B)
GDataTrojan.GenericKD.68797940
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R510883
VBA32Trojan.Sabsik.FL
ALYacTrojan.GenericKD.68797940
MAXmalware (ai score=88)
MalwarebytesMalware.AI.1357877039
TrendMicro-HouseCallTROJ_GEN.R002H09HL23
IkarusTrojan.Win64.Rozena
MaxSecureTrojan.Malware.216104763.susgen
FortinetPossibleThreat.PALLAS.M
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.1357877039?

Malware.AI.1357877039 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment