Malware

Malware.AI.2248779503 (file analysis)

Malware Removal

The Malware.AI.2248779503 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2248779503 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Malware.AI.2248779503?


File Info:

name: 667741E3909062499B91.mlw
path: /opt/CAPEv2/storage/binaries/ebf2e964a9c2f792cba84a72638037c7d1a55d1b5274ef43f819e607ad2bad7e
crc32: 42326517
md5: 667741e3909062499b9188ecc0bc2cea
sha1: 98cbcb7bdf74fbb86f346e56af568cdad588dc06
sha256: ebf2e964a9c2f792cba84a72638037c7d1a55d1b5274ef43f819e607ad2bad7e
sha512: 5b1f0d34c93b76c69e40ad473cc82cb69b33180de28e829f61961aa6f19e2c9434141c9bf2ed848878251bc6624d02b37e99557729c794daac69bd6c4a93e55e
ssdeep: 384:qX9xaGY5Go59orphKFrn3X2acdT3gw0rosPTICQxHnHnxpnH:2teIphKFTnEdL50rosTkHxpH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161629E932E29F776D78081B5147F57613E04502882EE9DE33EB61B382E94468E71B14E
sha3_384: a640bfcfd29078575d2f843004befa314f86e163e7dd626b47e18504281260eac6c6ad9b6d921e014584d3d3a456cc7e
ep_bytes: 60be008040008dbe0090ffff57eb0b90
timestamp: 2007-09-10 10:47:35

Version Info:

0: [No Data]

Malware.AI.2248779503 also known as:

DrWebTrojan.DownLoader.52980
MicroWorld-eScanTrojan.Generic.8461198
FireEyeGeneric.mg.667741e390906249
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Generic.8461198
CylanceUnsafe
ZillyaDownloader.Agent.Win32.66529
SangforSuspicious.Win32.Save.a
K7AntiVirusRootKit ( 0055e3fe1 )
K7GWRootKit ( 0055e3fe1 )
Cybereasonmalicious.390906
BitDefenderThetaAI:Packer.EA6592EE1B
CyrenW32/S-0b54b2a8!Eldorado
SymantecDownloader
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Rootkit.Agent.NDB
APEXMalicious
ClamAVWin.Downloader.14097-2
KasperskyTrojan-Downloader.Win32.Agent.ein
BitDefenderTrojan.Generic.8461198
NANO-AntivirusTrojan.Win32.Agent.cqjggy
AvastWin32:Malware-gen
Ad-AwareTrojan.Generic.8461198
EmsisoftTrojan.Generic.8461198 (B)
ComodoTrojWare.Win32.Rootkit.Agent.NDB@117x
BaiduWin32.Rootkit.Agent.au
VIPRETrojan.Generic.8461198
TrendMicroTSPY_LAQMA.SMI
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminesuspicious.low.ml.score
SophosML/PE-A + Troj/Dloadr-BED
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Generic.8461198
JiangminTrojanDownloader.Agent.nrb
GoogleDetected
AviraTR/Drop.Agent.NEM.2
Antiy-AVLTrojan/Generic.ASMalwS.13
ArcabitTrojan.Generic.D811B8E
ViRobotTrojan.Win32.Downloader.15896.B
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R10220
Acronissuspicious
McAfeegeneric!bg.eox
MAXmalware (ai score=83)
VBA32BScope.Trojan.Agent
MalwarebytesMalware.AI.2248779503
TrendMicro-HouseCallTSPY_LAQMA.SMI
RisingTrojan.Rootkit!1.AEDA (CLASSIC)
YandexTrojan.GenAsa!h96gzF8YkWE
IkarusTrojan.Zlob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dloader.BDS!tr
AVGWin32:Malware-gen
PandaBck/LanMan.AS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2248779503?

Malware.AI.2248779503 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment