Malware

What is “Malware.AI.3223677187”?

Malware Removal

The Malware.AI.3223677187 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3223677187 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Starts servers listening on 127.155.66.88:80
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

How to determine Malware.AI.3223677187?


File Info:

crc32: 12AA692B
md5: 2e063cd9e6d3d6141dc182fae8af3734
name: 2E063CD9E6D3D6141DC182FAE8AF3734.mlw
sha1: 2d1633bed84d5f44f44199c02980d8df3f55bef9
sha256: c8c0ad33e1577dd135105ecebb90a0ded72efcc587fac3a3e58f8531b5cf5bcc
sha512: bae05fcc82855646b76a7c7294bb3673197d7fd4a856fdd8c816e14a0a5656484d19e74264c4f0b7127364be50bb330b0db721205d0ce6103729a68dd72526bb
ssdeep: 12288:rr1ALEBDnZOCVwrx24EjFfQVC6sOGwWSKn74H:31AL8UjcjJLwWSmY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Error13Tracer, 2021
InternalName: SwimWatchActivator.exe
FileVersion: 1.0.0.0
CompanyName: Error13Tracer
ProductName: SwimWatchActivator
ProductVersion: 1.0.0.0
FileDescription: SwimWatch Race Analyzer Activator
OriginalFilename: SwimWatchActivator.exe
Translation: 0x0400 0x04b0

Malware.AI.3223677187 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Wacatac
ALYacGen:Trojan.Heur.Bi0@!xmFLNgc
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Hupigon.8adf66a9
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9e6d3d
CyrenW32/RLPacked.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Trojan.Heur.Bi0@!xmFLNgc
ViRobotTrojan.Win32.Z.Wacatac.453551
MicroWorld-eScanGen:Trojan.Heur.Bi0@!xmFLNgc
TencentWin32.Trojan.Crypt.Hrfi
Ad-AwareGen:Trojan.Heur.Bi0@!xmFLNgc
SophosML/PE-A
BitDefenderThetaAI:Packer.76EADC351C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Picsys.gc
FireEyeGeneric.mg.2e063cd9e6d3d614
EmsisoftGen:Trojan.Heur.Bi0@!xmFLNgc (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Poison.bmz
AviraTR/Crypt.ZPACK.Gen
MicrosoftBackdoor:Win32/Bladabindi!ml
GridinsoftTrojan.Heur!.038124E1
AegisLabTrojan.Win32.Xmflngc.4!c
GDataGen:Trojan.Heur.Bi0@!xmFLNgc
McAfeeArtemis!2E063CD9E6D3
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3223677187
TrendMicro-HouseCallTROJ_GEN.R002H0CEA21
RisingTrojan.Crypto!8.364 (CLOUD)
YandexPacked/RLPack
IkarusBackdoor.Win32.Hupigon
MaxSecureTrojan.Malware.117767791.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.3223677187?

Malware.AI.3223677187 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment