Malware

Malware.AI.2688753294 information

Malware Removal

The Malware.AI.2688753294 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2688753294 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2688753294?


File Info:

name: 4F9ECEFDF30957BC31FC.mlw
path: /opt/CAPEv2/storage/binaries/44085784762e441b2fd4b3c9606941b2b3861728fe2bc11764a2ae3746eccdfd
crc32: 344CAFF0
md5: 4f9ecefdf30957bc31fc6477c22b464a
sha1: 5a2c049da417683a90613b85a03ff65d780f9320
sha256: 44085784762e441b2fd4b3c9606941b2b3861728fe2bc11764a2ae3746eccdfd
sha512: fefd7a49d8740d9b4cd6d905d605c934eb4ce2adea6571f62507142adc21b3347ae6d118940bbfe00263b79b4d4ccd0e855797bcec0e785b1168bb85fb23d212
ssdeep: 384:TgEaziQIBt8yguzjEBNQiviL//U8zYpDc7+57ERkhNAdrHz0ez:T7a/6BlSvW//pzW7QBgI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4B3F8F23FC99B3EF33FDEB588F580DAA82574115C52941D6088864F0863692DDFCA1A
sha3_384: f9037eb4038bdbd9305947f2850b8284b73f28e7f077228fdaf5e64936a357aab7be9b0c39b5b7b22763df8a68cf4fbb
ep_bytes: 837c24120ae8b6ffffff29d101c1e889
timestamp: 2004-05-28 09:53:59

Version Info:

0: [No Data]

Malware.AI.2688753294 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61185288
FireEyeGeneric.mg.4f9ecefdf30957bc
CAT-QuickHealTrojan.Upatre.ZZ4
ALYacTrojan.GenericKD.61185288
MalwarebytesMalware.AI.2688753294
VIPRETrojan.GenericKD.61185288
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaTrojanDownloader:Win32/Upatre.1a94b5f4
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.df3095
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Upatre.NM.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Delf.gen
BitDefenderTrojan.GenericKD.61185288
NANO-AntivirusTrojan.Win32.Vundo.fncedi
SUPERAntiSpywareTrojan.Agent/Gen-DownloaderUpatre
AvastWin32:Waski-B [Cryp]
TencentTrojan.Win32.Delf.wd
SophosTroj/Zbot-HMB
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.19947
ZillyaDownloader.Upatre.Win32.70481
TrendMicroTROJ_UPATRE.SM5
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.61185288 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fqcv
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Waski.B@80t362
ArcabitTrojan.Generic.D3A59D08
ViRobotTrojan.Win.Z.Upatre.117054
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
MicrosoftTrojanDownloader:Win32/Upatre.A
GoogleDetected
AhnLab-V3Trojan/Win.Upatre.R477425
McAfeePWSZbot-FMO!4F9ECEFDF309
VBA32TrojanDownloader.Upatre
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.21026
TrendMicro-HouseCallTROJ_UPATRE.SM5
RisingDownloader.Upatre!8.B5 (TFE:5:nWFyk4X9xiM)
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
BitDefenderThetaGen:NN.ZexaF.36196.hmY@aebg6tni
AVGWin32:Waski-B [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2688753294?

Malware.AI.2688753294 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment