Malware

Malware.AI.1373216716 (file analysis)

Malware Removal

The Malware.AI.1373216716 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1373216716 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1373216716?


File Info:

name: 7B63D8FEAB77315FE852.mlw
path: /opt/CAPEv2/storage/binaries/80b5f4d85b2ee5b38a907ba849ad754127c85f6312efb87593bd2406bdbf3ea5
crc32: A61CBFF0
md5: 7b63d8feab77315fe852fac71009e1b3
sha1: a18fce4d005dde5453292aa3d20b7ce891498997
sha256: 80b5f4d85b2ee5b38a907ba849ad754127c85f6312efb87593bd2406bdbf3ea5
sha512: 25b1bc4882f3c8ca13d2cfa4d2b5547d67c83b952eff923877e47d0eaad83760073983e1807c409e94408a8ad3b7d2d2c511ef488f1c21ea7d4f17a795a5290d
ssdeep: 12288:86Wq4aaE6KwyF5L0Y2D1PqLcpNYIV2p8fBw2B2vCm2:6thEVaPqLUYK4AMqH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2E47C6194292479C3FB02770653D64068B41F4EB96F6E3DA026BFD23BFE3C22905D62
sha3_384: 9738f17e2b2b755ddb1a8314d80069e0124aa533f3f9f1e89b107c4c426080e79b61e587f2d4165ac87e41ba9f85b631
ep_bytes: 60be00c049008dbe0050f6ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileVersion: 15.0.4535.1000
FileDescription: SolidShare Unattended Installer
LegalCopyright: © 2013 By Extended
ProductName: Microsoft Office Professional Plus 2013
ProductVersion: 15.0.4535.1000
Hazırlayan: tended
CompanyName: SolidShare Team
Translation: 0x041f 0x04b0

Malware.AI.1373216716 also known as:

LionicTrojan.Win32.Generic.4!c
SkyhighBehavesLike.Win32.BadFile.jc
MalwarebytesMalware.AI.1373216716
ZillyaTrojan.AutoIT.Win32.177298
K7AntiVirusTrojan ( 700000111 )
AlibabaPacked:Win32/Infostealer.b82d8d14
K7GWTrojan ( 700000111 )
Cybereasonmalicious.d005dd
SymantecTrojan.Gen.9
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Packed.Autoit.H suspicious
APEXMalicious
AvastWin32:Malware-gen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
WebrootW32.Malware.Gen
Antiy-AVLGrayWare/Autoit.BinToStr.a
Kingsoftmalware.kb.b.798
XcitiumMalware@#26nuo6xww0qpd
MicrosoftTrojan:Script/Phonzy.A!ml
McAfeeArtemis!7B63D8FEAB77
VBA32Trojan.Autoit.F
Cylanceunsafe
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
FortinetW32/Generic
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1373216716?

Malware.AI.1373216716 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment