Malware

Malware.AI.3427027731 (file analysis)

Malware Removal

The Malware.AI.3427027731 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3427027731 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.3427027731?


File Info:

name: 745D0FB104BA5D10DC68.mlw
path: /opt/CAPEv2/storage/binaries/af4ab7b3b7d5fc01b5177c0ae09d73e5ee0cd1dc6bf3549ba52d25d5715e799a
crc32: 92C85FF4
md5: 745d0fb104ba5d10dc68cda14e6b9acb
sha1: 36649c4c300b1a1d2e6967fb982b7c4f980a7a64
sha256: af4ab7b3b7d5fc01b5177c0ae09d73e5ee0cd1dc6bf3549ba52d25d5715e799a
sha512: ef426228537ac757cc6e107c1a3e88a019f81edba2bf422a5668099e1eae3658d0e3add043d979253c51f08f769df36c731fb2ea39ec115985444413bb79ac32
ssdeep: 12288:bkVZmIuF37SkEj292B2E/Xj49Yi8+c0TWAb/:bkVZmIuF3WkR9sXMle0TWA7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBB4BE23A26185A7E03505B586B30B36BB7476521E71876F8BC0CEB52E637309F6B71C
sha3_384: a85a1c50088be20a715d7b77402d1106fc9543d3feb631763708169bcecf9128145bb302f245ee26387e370eb5b45ff3
ep_bytes: 558bec6aff68584f43006864ab420064
timestamp: 2023-06-25 10:11:36

Version Info:

FileVersion: 1.0.0.1
FileDescription: Conster 5
ProductName: Conster 5
ProductVersion: 1.0.0.1
CompanyName: Conster 5
LegalCopyright: Conster 5
Comments: Conster 5
Translation: 0x0804 0x04b0

Malware.AI.3427027731 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.67793927
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.745d0fb104ba5d10
McAfeeArtemis!745D0FB104BA
Cylanceunsafe
SangforTrojan.Win32.Save.BlackMoon
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005931081 )
K7AntiVirusTrojan ( 005931081 )
ArcabitTrojan.Generic.D40A7407
BitDefenderThetaGen:NN.ZexaF.36318.Hq3@a8kK4Lbb
CyrenW32/ABRisk.EDYD-2601
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.CobaltStrike
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.67793927
AvastWin64:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11afd4b4
SophosBlackMoon Packed (PUA)
VIPRETrojan.GenericKD.67793927
TrendMicroTROJ_GEN.R002C0WFT23
McAfee-GW-EditionBehavesLike.Win32.Infected.hh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.67793927 (B)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Win32.Blamon.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataWin32.Application.PSE.1ETEWJE
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5446951
Acronissuspicious
VBA32BScope.DDoS.Npf
ALYacTrojan.GenericKD.67793927
MAXmalware (ai score=81)
MalwarebytesMalware.AI.3427027731
TrendMicro-HouseCallTROJ_GEN.R002C0WFT23
RisingTrojan.Agent!8.B1E (TFE:5:ZY7kB2TgTVH)
IkarusAdWare.Win32.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.WP!tr
AVGWin64:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.3427027731?

Malware.AI.3427027731 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment