Malware

Malware.AI.2348110240 (file analysis)

Malware Removal

The Malware.AI.2348110240 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2348110240 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine Malware.AI.2348110240?


File Info:

name: 636CFA55435F48B13047.mlw
path: /opt/CAPEv2/storage/binaries/3bd6251fce65576040657513dd14a9a62d959f5b6fd166d14e21f14622e40102
crc32: CE617614
md5: 636cfa55435f48b13047666f42117df1
sha1: 403191e4e24a7dcac70f138bb6a2f5e8801dd951
sha256: 3bd6251fce65576040657513dd14a9a62d959f5b6fd166d14e21f14622e40102
sha512: 1c34fad5f2e85efc3b42420b7983fad55fc33d69556fe60f3f6110c94ce02df7739c1252861f8cb59b6e24ec04d81bc8c2aa776690502a28c59b710887a9002b
ssdeep: 3072:TCL5Ez966N8BGHDBMgUj0Xlc5sa/wTD3wCveBbjqoIKp7mV1tvX8ow6bGODbbbGi:A5qWjj0u5T/4DAC2b+67gfwEDbDFff
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D749D107645C472D9A202B1897E9F1BA23CBA05076499CFE3DC4EA92FB17C22F36757
sha3_384: 5a2cee349afb6d70e145cc36fdce9c7ca1fa72a6ad7bec67d6f8e685296ecafd9d2493673cdf0afccf37dc334068d5ee
ep_bytes: e8ad8d0000e97ffeffff558bec8b4514
timestamp: 2015-12-11 23:46:12

Version Info:

0: [No Data]

Malware.AI.2348110240 also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Generic.o!c
MicroWorld-eScanApplication.Agent.GKV
CylanceUnsafe
Paloaltogeneric.ml
SophosGeneric ML PUA (PUA)
BaiduWin32.Worm.Agent.u
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Rbot.B
JiangminWorm.Pajetbin.j
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacApplication.Agent.GKV
MalwarebytesMalware.AI.2348110240
IkarusTrojan.Win32.Rbot
FortinetW32/DCom.AA!tr
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.2348110240?

Malware.AI.2348110240 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment