Malware

How to remove “Malware.AI.1389079071”?

Malware Removal

The Malware.AI.1389079071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1389079071 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Behavioural detection: Transacted Hollowing
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A possible heap spray exploit has been detected
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

Related domains:

example.org
ipv4only.arpa
detectportal.firefox.com
aus5.mozilla.org
firefox.settings.services.mozilla.com
content-signature-2.cdn.mozilla.net
www.4dots-software.com
support.mozilla.org
contile.services.mozilla.com
shavar.services.mozilla.com
push.services.mozilla.com
services.addons.mozilla.org
incoming.telemetry.mozilla.org
twitter.com
github.com
www.youtube.com
www.facebook.com
www.wikipedia.org
www.reddit.com
wpad.local-net

How to determine Malware.AI.1389079071?


File Info:

name: CD7A15DC85379DD88B4B.mlw
path: /opt/CAPEv2/storage/binaries/9847c42c9df72fdd09799e13ff728b32530a263da782f411b79e0a9082af6831
crc32: AAB400AC
md5: cd7a15dc85379dd88b4b58361fe7454f
sha1: 88c2d6345c8750cd5975391ae4fc6a0602dc2f80
sha256: 9847c42c9df72fdd09799e13ff728b32530a263da782f411b79e0a9082af6831
sha512: 6374afdc818aedf2a6a234c4ac45eda0e78d3d68e8f4e0fa16ae989f4e714a57f7f4974676395c8f61185621421e50aa95aacc9f77b418eeaf0dc7b8c420a17a
ssdeep: 6144:EDO4bBD0dv6ck9BMbnafgLI+l4w/Y1z+N0m1nitprVscUX/2:WVadv6ckk7TsQ4716B1kprVsR/2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A64220462F0C67BCAB907F1A8B2E5566F77ED140255234353807A463967683AA3F39F
sha3_384: 843c9690ad0296757c961d980a7bc1fc1f4107262582e49a707e6df3185f95ca0b45c4114cbd3144e279b4da535968d4
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2018-01-30 03:57:45

Version Info:

0: [No Data]

Malware.AI.1389079071 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.RegRun.4!e
MicroWorld-eScanGen:Variant.Bulz.292465
FireEyeGen:Variant.Bulz.292465
McAfeeArtemis!CD7A15DC8537
CylanceUnsafe
SangforTrojan.MSIL.Bobik.gen
Cybereasonmalicious.c85379
CyrenW32/Trojan.SATK-5041
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/4Dots.A potentially unwanted
APEXMalicious
KasperskyUDS:Trojan-Spy.MSIL.Bobik.gen
BitDefenderGen:Variant.Bulz.292465
NANO-AntivirusTrojan.Win32.4Dots.iuzlfz
AvastWin32:Malware-gen
TencentMsil.Trojan-spy.Bobik.Tays
SophosGeneric PUA II (PUA)
ZillyaTrojan.Bobik.Win32.2670
McAfee-GW-EditionBehavesLike.Win32.Vopak.fc
EmsisoftGen:Variant.Bulz.292465 (B)
GDataGen:Variant.Bulz.292465
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Bulz.311143
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32TrojanSpy.MSIL.Bobik
ALYacGen:Variant.Bulz.292465
MAXmalware (ai score=87)
MalwarebytesMalware.AI.1389079071
TrendMicro-HouseCallTROJ_GEN.R002H07KS21
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Malware.AI.1389079071?

Malware.AI.1389079071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment