Malware

Malware.AI.2378175857 (file analysis)

Malware Removal

The Malware.AI.2378175857 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2378175857 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2378175857?


File Info:

name: 3C7399FE77946AAE7F59.mlw
path: /opt/CAPEv2/storage/binaries/8372befe0f98399ff9648f547f7b99d6a3422cd92454181ff38782d9a0bad2aa
crc32: 4DA69523
md5: 3c7399fe77946aae7f5911f1c86c6810
sha1: 1f173a2869a0e8d41bc66c773bd1069fcaad2f5a
sha256: 8372befe0f98399ff9648f547f7b99d6a3422cd92454181ff38782d9a0bad2aa
sha512: c5be18edcdf9083738add22fdfcfb03e9022485b526a798212cf0dd0c734a03c8a8bacec25146dcebc1495526eff189849157c23965386e3bbd274361b9771d4
ssdeep: 6144:vX1iZOwm5oA29MOI67WjWTL1NBTrQ1eYcQv/xDIQ7kdSSERSi0:f1ilcolrI6K6TTU1eKv/xcQK8Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F642236DA068936E7B0123621271A5C870AE032AD5B5BBBDC25FC5FFD741D8AD8107B
sha3_384: 4d3c09f10d957fe592f5f05943b7c025f7775a0e4b4d41c81a44c4a221ffad325a6d737d489d27313910413d534d5473
ep_bytes: 60be00f047008dbe0020f8ffc787c4a0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.2378175857 also known as:

LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.35
FireEyeGeneric.mg.3c7399fe77946aae
CAT-QuickHealBackdoor.Hupigon.20845
ALYacGen:Heur.Mint.Zard.35
CylanceUnsafe
ZillyaBackdoor.Hupigon.Win32.162743
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Heur.Mint.Zard.35
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e77946
BaiduWin32.Trojan.Hupigon.c
CyrenW32/Hupigon.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.Hupigon.L
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Delf-1518
KasperskyBackdoor.Win32.Hupigon.iypq
AlibabaBackdoor:Win32/Hupigon.8a2c3429
NANO-AntivirusTrojan.Win32.Hupigon.bjvuex
ViRobotBackdoor.Win32.Hupigon.704512.EW[UPX]
RisingBackdoor.Hupigon!1.64C6 (CLOUD)
Ad-AwareGen:Heur.Mint.Zard.35
EmsisoftGen:Heur.Mint.Zard.35 (B)
ComodoBackdoor.Win32.Hupigon.~J@fb0k9
DrWebBackDoor.Huai.7033
VIPREGen:Heur.Mint.Zard.35
TrendMicroMal_HPGN-9
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
Trapminemalicious.moderate.ml.score
SophosMal/SpyAgent-F
IkarusPacked.Win32.PePatch
JiangminBackdoor/Huigezi.2008.pah
AviraBDS/Hupigon.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Kryptor
GDataWin32.Trojan.PSE.14IIXYG
GoogleDetected
AhnLab-V3Trojan/Win32.Hupigon.C129721
Acronissuspicious
McAfeeArtemis!3C7399FE7794
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.2378175857
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_HPGN-9
TencentMalware.Win32.Gencirc.114cd1bc
YandexTrojan.GenAsa!hXthun7VHlI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Hupigon.NWS!tr
BitDefenderThetaAI:Packer.E9BD34D81D
AVGFileRepMalware [Trj]
AvastFileRepMalware [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2378175857?

Malware.AI.2378175857 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment