Malware

Malware.AI.3378948852 malicious file

Malware Removal

The Malware.AI.3378948852 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3378948852 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the CobaltStrikeBeacon malware family
  • Attempts to modify proxy settings

How to determine Malware.AI.3378948852?


File Info:

name: A3E4E3B34F8DCFA00EF2.mlw
path: /opt/CAPEv2/storage/binaries/e35dc94ec0597b8d596782988927ad56cb56e9f2338343a221e7fa2aa89bbfd9
crc32: EAEE0374
md5: a3e4e3b34f8dcfa00ef2df12f05085a1
sha1: 578b8fa86cfae2538a5acc000b68a1cf85b8f403
sha256: e35dc94ec0597b8d596782988927ad56cb56e9f2338343a221e7fa2aa89bbfd9
sha512: 70bd62de6014dd013c231fe7b9c106661eb724d3850f2fe5cb1dcfafb7b5f28e4d17db093e1de7cbf14d9f078a0479bce851155e62185a9482c27a369bdd6599
ssdeep: 12288:nhKnSqe31KBbVz/a593mYOjHx/tdJR44aLm9M1WmAk:hKnSqe31K1JU2FVtdJpW1I
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T144153A47E3B341FCC97BC97483A6A732A830785441397E395F45DB222F65F20A92EB64
sha3_384: d42d07fc55ceae0fd1965c58a5bb6bc4b5fbee984efa5534948e2a4e2929b98e14a8e238d19ccab91c44226f9e719d0e
ep_bytes: 4883ec28c705f26b0e0001000000e89d
timestamp: 2021-12-07 12:40:52

Version Info:

0: [No Data]

Malware.AI.3378948852 also known as:

LionicTrojan.Win32.Cobalt.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.61493
CAT-QuickHealBackdoor.Cobalt
ALYacGen:Variant.Tedy.61493
CylanceUnsafe
K7AntiVirusTrojan ( 0058b9421 )
AlibabaTrojan:Win32/Cobalt.d25d2df9
K7GWTrojan ( 0058b9421 )
Cybereasonmalicious.86cfae
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.CBT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.CobaltStrike-9914238-0
KasperskyTrojan.Win32.Cobalt.hoj
BitDefenderGen:Variant.Tedy.61493
AvastWin64:Malware-gen
TencentWin32.Trojan.Cobalt.Lnxs
Ad-AwareGen:Variant.Tedy.61493
SophosMal/Generic-S
F-SecureTrojan.TR/AD.CobaltSC.micim
TrendMicroTROJ_GEN.R002C0PLC21
McAfee-GW-EditionBehavesLike.Win64.AdwareTskLnk.dh
FireEyeGeneric.mg.a3e4e3b34f8dcfa0
EmsisoftGen:Variant.Tedy.61493 (B)
IkarusTrojan.Win64.Crypt
GDataGen:Variant.Tedy.61493
JiangminTrojan.Cobalt.wz
AviraTR/AD.CobaltSC.micim
MAXmalware (ai score=83)
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Tedy.DF035
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4830226
McAfeeRDN/Generic.dx
VBA32Backdoor.Cobalt
MalwarebytesMalware.AI.3378948852
TrendMicro-HouseCallTROJ_GEN.R002C0PLC21
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Kryptik.CBT!tr
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Malware.AI.3378948852?

Malware.AI.3378948852 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment