Malware

About “Malware.AI.2748044629” infection

Malware Removal

The Malware.AI.2748044629 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2748044629 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Malware.AI.2748044629?


File Info:

name: 96EC8798BBA011D5BE95.mlw
path: /opt/CAPEv2/storage/binaries/c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37
crc32: 4225E9B9
md5: 96ec8798bba011d5be952e0e6398795d
sha1: af7c73c47c62d70c546b62c8e1cc707841ec10e3
sha256: c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37
sha512: d002de37edd3df2f6751af06f7b25a2500b970eeb078e174bca8535624cfea6293636a11f4ee5c446383985b4099bebfbfb6f34b333ff5949e0df51f2edfc906
ssdeep: 98304:gP9cgRyyVyGHAeBSut+aFNnLlPLeqNZ8hY/1KbxabdDk1duupRWQgWseI9eIfbkr:C9hlX+aFFLlPKQ8hY/DkWWst9e4ge+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T121563365BCA988E3D7720C354AF3C076557DFE230F160593A66833AB1935B902A3DE6C
sha3_384: cb8220eae831ed98ac1fc0619cfdcba93156a47aeced31df1bf4caac7a21604e13feb08d3e182beefa11369fcf103123
ep_bytes: e822050000e987feffffcccccccccccc
timestamp: 2017-12-11 15:09:08

Version Info:

0: [No Data]

Malware.AI.2748044629 also known as:

LionicHacktool.Python.Impacket.3!c
MicroWorld-eScanTrojan.GenericKD.31812356
CAT-QuickHealHacktool.Python
ALYacMisc.Riskware.Impacket
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforHacktool.Python.Impacket.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaHacktool:Win32/Secretdmp.190417
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.ZOUV-9006
APEXMalicious
KasperskyUDS:HackTool.Python.Impacket.a
BitDefenderTrojan.GenericKD.31812356
Ad-AwareTrojan.GenericKD.31812356
EmsisoftTrojan.GenericKD.31812356 (B)
TrendMicroHackTool.Win32.Mpacket.SM
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.96ec8798bba011d5
SophosImpacket (PUA)
GDataTrojan.GenericKD.31812356
WebrootPUA.Gen
ArcabitTrojan.Generic.D1E56B04
ZoneAlarmHEUR:HackTool.Python.Impacket.gen
MicrosoftTrojan:Win32/Skeeyah.B!rfn
AhnLab-V3HackTool/Win.impacket.C4777703
McAfeeArtemis!96EC8798BBA0
MAXmalware (ai score=99)
MalwarebytesMalware.AI.2748044629
PandaPUP/Hacktool
TrendMicro-HouseCallHackTool.Win32.Mpacket.SM
eGambitTrojan.Generic
FortinetRiskware/Secretdmp
Cybereasonmalicious.8bba01
MaxSecureTrojan.Malware.109441793.susgen

How to remove Malware.AI.2748044629?

Malware.AI.2748044629 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment