Malware

Malware.AI.3154966120 (file analysis)

Malware Removal

The Malware.AI.3154966120 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3154966120 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Created a service that was not started

How to determine Malware.AI.3154966120?


File Info:

name: 2968BC1D879E0C10D495.mlw
path: /opt/CAPEv2/storage/binaries/1f10968c9937e6734f6b1149b21bbbbdb15ff95bd6cd8e6e8da393e6760aefd2
crc32: C343A60F
md5: 2968bc1d879e0c10d4959cc433a48bbe
sha1: b458a7b8d3019cb96eff3445045e3398eef1ff07
sha256: 1f10968c9937e6734f6b1149b21bbbbdb15ff95bd6cd8e6e8da393e6760aefd2
sha512: b03e3d9f42d9ef71c141db674b156c8b137698860c7de243a5d4b5e0402f681b05d5419364e62fc4e38b827ff3326d37c2717fa583a72c245ed0ce0d7b5c6289
ssdeep: 49152:IFsaqt6PUzPkSz2rsGODdsmrUZOFGr5BaY+tKNYD5N1:ICaqom9z2rsPBrUZTgV1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDB51262B2D08477D0232D789D0F96A854267E522D24AC4F37E87E8C6F77381352F69B
sha3_384: 858251ff6107d661e29ff3096f104a2080c35207d0f78627040ded61854ee080c9475e26b3c7d6f093210cb185095b7b
ep_bytes: 558bec83c4f0b8acb54500e8549efaff
timestamp: 2013-01-16 16:26:46

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Malware.AI.3154966120 also known as:

DrWebTrojan.Siggen5.11223
MicroWorld-eScanGen:Trojan.Malware.tM0@a82FzgeO
FireEyeGeneric.mg.2968bc1d879e0c10
McAfeeArtemis!2968BC1D879E
CylanceUnsafe
ZillyaTrojan.Fsysna.Win32.21580
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Trojan.Win32.Fsysna.gen
BitDefenderGen:Trojan.Malware.tM0@a82FzgeO
NANO-AntivirusTrojan.Win32.TrjGen.epompe
Ad-AwareGen:Trojan.Malware.tM0@a82FzgeO
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
EmsisoftGen:Trojan.Malware.tM0@a82FzgeO (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Malware.tM0@a82FzgeO
JiangminTrojan.Fsysna.mna
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Malware.E757AD
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32BScope.Adware.Gamsofts
ALYacGen:Trojan.Malware.tM0@a82FzgeO
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3154966120
APEXMalicious
RisingMalware.Heuristic!ET#76% (RDMK:cmRtazp499Pi96kNuRoVWBJuaMIa)
YandexTrojan.GenAsa!KVWeWEzfGl0
eGambitUnsafe.AI_Score_95%
FortinetW32/PossibleThreat
Cybereasonmalicious.d879e0
PandaTrj/CI.A

How to remove Malware.AI.3154966120?

Malware.AI.3154966120 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment