Malware

Should I remove “Malware.AI.3348024760”?

Malware Removal

The Malware.AI.3348024760 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3348024760 virus can do?

  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.3348024760?


File Info:

name: 2754C9191A20E2E19560.mlw
path: /opt/CAPEv2/storage/binaries/a59c00452834f63139d0995fba021d2a87b1bbad30ff84c8362e68cc0293a864
crc32: ABA50F8D
md5: 2754c9191a20e2e19560c15d4d6370be
sha1: 0d5b0645db4438b278adfd95723522f992a19be9
sha256: a59c00452834f63139d0995fba021d2a87b1bbad30ff84c8362e68cc0293a864
sha512: 821db71b81d3802df35dfdb625afe050fe56d4cfa59dbb08793a782d34de6a3a9872fbd69b7a4400145600d647d0f832158e1e1cd9893b0df7b1565a4f0aacae
ssdeep: 49152:DwASTAqC/Caf2aIp8swXC5T6GN2R8XXx:b/8Cs3rNR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153956D12B285983BC07F1F3B4D6B96A86C3B7A302E558C5B6EFC4A4C0F356416D3664B
sha3_384: c4031f29161e383c344bfd958c60af8b3097feac9d3157fe98d942e3ab0eabc39394e06c10c52910c8a73810e6dc051f
ep_bytes: 558bec83c4f053b820525500e8abb2ea
timestamp: 2018-10-08 23:29:10

Version Info:

0: [No Data]

Malware.AI.3348024760 also known as:

LionicTrojan.Win32.BestaFera.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.383430
ALYacGen:Variant.Zusy.383430
CylanceUnsafe
ZillyaTrojan.BestaFera.Win32.6783
SangforTrojan.Win32.AGEN.1020568
K7AntiVirusTrojan-Downloader ( 004e02e81 )
AlibabaTrojanBanker:Win32/BestaFera.1fc0745c
K7GWTrojan-Downloader ( 004e02e81 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.XZU
APEXMalicious
ClamAVWin.Downloader.Zusy-9884239-0
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderGen:Variant.Zusy.383430
NANO-AntivirusTrojan.Win32.BestaFera.fizcve
AvastWin32:Malware-gen
TencentWin32.Trojan-banker.Bestafera.Hqlo
Ad-AwareGen:Variant.Zusy.383430
SophosMal/Generic-S
ComodoMalware@#3lsz2t8ro1zcq
DrWebTrojan.DownLoader27.9600
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.2754c9191a20e2e1
EmsisoftGen:Variant.Zusy.383430 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1101496
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2886589
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Zusy.383430
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.C24058
Acronissuspicious
McAfeeArtemis!2754C9191A20
VBA32BScope.TrojanBanker.BestaFera
MalwarebytesMalware.AI.3348024760
YandexTrojan.GenAsa!7MxPa1AUJGA
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.XZU!tr.dldr
BitDefenderThetaAI:Packer.5AF8995821
AVGWin32:Malware-gen
Cybereasonmalicious.91a20e
PandaTrj/GdSda.A

How to remove Malware.AI.3348024760?

Malware.AI.3348024760 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment