Malware

About “Malware.AI.3359747389” infection

Malware Removal

The Malware.AI.3359747389 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3359747389 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Collects information to fingerprint the system

How to determine Malware.AI.3359747389?


File Info:

name: DCCBB5440ED57F476B99.mlw
path: /opt/CAPEv2/storage/binaries/b03ba6f1e742e27aac2d8c6f2eb09b45cd302a8101cf11d2f70c251f930ec823
crc32: A2054649
md5: dccbb5440ed57f476b99f8effd267364
sha1: b0e633b6b0f85679403aab6003b32298c4bfc129
sha256: b03ba6f1e742e27aac2d8c6f2eb09b45cd302a8101cf11d2f70c251f930ec823
sha512: 8f35c8fe9603022260e643b19fdbe61d4b5f0f4a9294b5bef2a0a33c2873d127f94f70e57b2101bbf0b72097da211bd81938490b436555b7924465b63d0a4683
ssdeep: 6144:T44b7czK+MOjoF3/di++08qvFsRcfJgohePbrzZ7tfYIKpnzrDgtZO:84fijVjo1FimlvybohePptgIqL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB64F13C80EC3C6FD8857877559AA19B55614F227AF3D9EBE01831B3CA190E1A73252F
sha3_384: 5c2d5cb4ce8e37d511eb5c237959c381353b925cf5ff39955513b7f77c3a4c8056afaac520769584da14fce1c6afe59c
ep_bytes: 558bec81ec14020000689c694300ff15
timestamp: 2013-08-23 06:49:47

Version Info:

CompanyName: Корпорация М айкрософт
FileDescription: Диспетчер синхронизации
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
Translation: 0x0419 0x04b0

Malware.AI.3359747389 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.dccbb5440ed57f47
CAT-QuickHealTrojanDropper.Gepys.A
McAfeePacked-AM!DCCBB5440ED5
CylanceUnsafe
VIPRETrojan.Win32.ZAccess.ma (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040fa341 )
BitDefenderTrojan.GenericKD.48230483
K7GWTrojan ( 0040fa341 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Kryptik.ac
VirITTrojan.Win32.Generic.BHQD
CyrenW32/Zaccess.BC.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.BIRD
APEXMalicious
ClamAVWin.Trojan.Agent-1327030
KasperskyTrojan.Win32.ShipUp.ebwd
NANO-AntivirusTrojan.Win32.ShipUp.crnkaf
MicroWorld-eScanTrojan.GenericKD.48230483
RisingDropper.Gepys!8.15D (TFE:dGZlOgKDkLrDq2mUaA)
Ad-AwareTrojan.GenericKD.48230483
EmsisoftTrojan.GenericKD.48230483 (B)
ComodoTrojWare.Win32.Kryptik.BIWI@51iu3y
DrWebTrojan.Mods.1
ZillyaTrojan.Kryptik.Win32.770473
TrendMicroTROJ_KRYPTK.SML2
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
SophosML/PE-A + Troj/Agent-ADXT
IkarusTrojan.Win32.ShipUp
JiangminTrojan/ShipUp.vl
AviraTR/Kryptik.jduefs
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3B62D0
MicrosoftTrojan:Win32/Zbot.SIBL!MTB
GDataTrojan.GenericKD.48230483
AhnLab-V3Backdoor/Win32.ZAccess.R80805
Acronissuspicious
VBA32BScope.P2P-Worm.Palevo
ALYacTrojan.GenericKD.48230483
TACHYONTrojan/W32.Shipup.326904
MalwarebytesMalware.AI.3359747389
PandaGeneric Malware
TrendMicro-HouseCallTROJ_KRYPTK.SML2
TencentMalware.Win32.Gencirc.10b0f04c
YandexTrojan.GenAsa!H6ySIOz1nrQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIPQ!tr
BitDefenderThetaGen:NN.ZexaF.34212.tu3@ayRXRahc
AVGWin32:Kryptik-MTH [Trj]
Cybereasonmalicious.40ed57
AvastWin32:Kryptik-MTH [Trj]
MaxSecureTrojan.ShipUp.gen

How to remove Malware.AI.3359747389?

Malware.AI.3359747389 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment