Malware

What is “Malware.AI.3130681031”?

Malware Removal

The Malware.AI.3130681031 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3130681031 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server

How to determine Malware.AI.3130681031?


File Info:

name: 3C21BEA59FCE18F23FFF.mlw
path: /opt/CAPEv2/storage/binaries/a487fa9c36bff6da1ff8318d64dea0e8c3ee2167edaf80bb04dab2747579e43f
crc32: 09651BCF
md5: 3c21bea59fce18f23fff5a2d6c6faf07
sha1: 9cb52764a30d58ed8ceb22457b4e9159aafb30b5
sha256: a487fa9c36bff6da1ff8318d64dea0e8c3ee2167edaf80bb04dab2747579e43f
sha512: 21da7ffc76d82382aed0aef00fe609dabc5aa5225ba6fe5ebdaadd5f5d2fdad4532dd00686d0f05f40ec2dbd76e18327f64adeb0134b4d707437292e588b2e37
ssdeep: 768:oXJmnpEgtbMrp5b+lmAquUYQkCNvUiTS2sWG0khv9uThoYj:oX8RtbMrbb8npO1PT7sWBThoK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12903E048E3AD466EF06503BC5C72339027BEBA206A5E47A5308C10F76FDF588899577B
sha3_384: 09f564dafb061312fbd0e364a79bd4ec31fe34e68120a3a176e4b5ea3b8afc63ee940d621d677afb769dcd6cd31781d5
ep_bytes: 60be002041008dbe00f0feff57eb0b90
timestamp: 2020-07-10 09:09:45

Version Info:

0: [No Data]

Malware.AI.3130681031 also known as:

MicroWorld-eScanGen:Variant.Graftor.848154
FireEyeGeneric.mg.3c21bea59fce18f2
McAfeeGenericRXAA-FA!3C21BEA59FCE
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00572bcd1 )
K7GWTrojan-Downloader ( 00572bcd1 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.34742.cmHfaW5rnKgi
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Small.BGX
APEXMalicious
BitDefenderGen:Variant.Graftor.848154
NANO-AntivirusTrojan.Win32.Small.icbwmw
AvastWin32:RootkitX-gen [Rtk]
TencentMalware.Win32.Gencirc.11c48743
Ad-AwareGen:Variant.Graftor.848154
SophosGeneric ML PUA (PUA)
ZillyaDownloader.Small.Win32.144746
McAfee-GW-EditionGenericRXMO-SF!FCD55D2C6E33
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Graftor.848154 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.848154
AviraTR/Dldr.Small.lbwqe
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab08.Exp
Acronissuspicious
ALYacGen:Variant.Graftor.848154
MAXmalware (ai score=85)
MalwarebytesMalware.AI.3130681031
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.DL.Small!GHAexR6yyK8
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GMUU!tr
AVGWin32:RootkitX-gen [Rtk]
Cybereasonmalicious.59fce1

How to remove Malware.AI.3130681031?

Malware.AI.3130681031 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment