Malware

Should I remove “Malware.AI.2021648368”?

Malware Removal

The Malware.AI.2021648368 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2021648368 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2021648368?


File Info:

name: CDD26265FC3FCC2A2079.mlw
path: /opt/CAPEv2/storage/binaries/0d358aaf259883b1a7c7b43b149baec95020aae776672d7244361ac5a9b328d5
crc32: CBB949A2
md5: cdd26265fc3fcc2a2079bcb7eaf546bb
sha1: 0ce68988347a312539bf48d21e1388d874cf2af2
sha256: 0d358aaf259883b1a7c7b43b149baec95020aae776672d7244361ac5a9b328d5
sha512: 20f5d102450c36eaacd1c0f46b919dc4d07bf2e78dabfb31c5156aeee410b98c68865d10c424ae99677ac56cb54c31a8b4725a264918bf5a6ffed72fdd169b52
ssdeep: 49152:AEutzfsCG5h9aIz0Udm51AhCOZV60hPSqJxfW2QsdS9fJDZHImyV4:yzECG5hna1Ax6EaqfuCdgxOmyV4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14FC501027391C062FFAB91734F5AF2515BBCBA260127A51F13A81DB9BD701B1173E7A2
sha3_384: 642c5a13330dd248db28c33b7d292476c9adefb2730fc25afc3f2c812a411b4ed74f8b8eb1909f7646fba5a4b0e420f7
ep_bytes: e86e050000e97afeffff558bec56ff75
timestamp: 2020-12-20 02:30:31

Version Info:

FileDescription: Clash of Clans Bot - A Free Clash of Clans bot - https://mybot.run
FileVersion: 7.8.9
LegalCopyright: © https://mybot.run
ProductName: My Bot
ProductVersion: 7.8
Translation: 0x0809 0x04b0

Malware.AI.2021648368 also known as:

CyrenCloudRisk/WIN_PE.0d358aaf!Threatlookup
BkavW32.Common.BC135FE1
LionicTrojan.Win32.Generic.4!c
ClamAVWin.Trojan.Agent-6825810-0-6852456-0
FireEyeGeneric.mg.cdd26265fc3fcc2a
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!CDD26265FC3F
Cylanceunsafe
ZillyaTrojan.Obfuscated.Win32.95080
SangforTrojan.Win32.Agent.V0er
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
AvastWin32:Malware-gen
SophosMal/Generic-S
JiangminAdWare.Script.gj
WebrootPua.Hax
GoogleDetected
Antiy-AVLTrojan[Spy]/Win32.Autoit
MicrosoftTrojan:Win32/Ymacco.AA0D
MAXmalware (ai score=61)
VBA32Trojan.Ymacco
MalwarebytesMalware.AI.2021648368
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.111808503.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2021648368?

Malware.AI.2021648368 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment