Malware

Malware.AI.3448113302 (file analysis)

Malware Removal

The Malware.AI.3448113302 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3448113302 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

How to determine Malware.AI.3448113302?


File Info:

name: 2796192EC00B9FE3E9FB.mlw
path: /opt/CAPEv2/storage/binaries/b013d635e3fa6aa9f6e202641e7922e09b6138abb5d43f41d072a3137bdac041
crc32: 1D81B8AE
md5: 2796192ec00b9fe3e9fbc4897f91ed65
sha1: abcab8e8adc0f532e43acc82a9c363dbb0a18160
sha256: b013d635e3fa6aa9f6e202641e7922e09b6138abb5d43f41d072a3137bdac041
sha512: 88cbad8e414e87b045a64b9a81ec4541b07c56a80c232b22a6d330d0c7771de2beb2b9bea36b031f331d98fb246367f3540e66b0d7f054addc7437b759770df5
ssdeep: 49152:nvoI5cb9iyjnw6TbRkQgtg6iI1LMm6bq0Bl+5mI5:QIiRiy7w6hQF6mi7N+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B95332DFE50C8F8D2A12D704A135E1B2A772741A94AA7EF53F173201EBF4D28453D6A
sha3_384: 72087d08997afd8dacf75a8a032a8c042505e68a29be504c58b4e04d1f76214e05711868788441a5a3c388f0376502ce
ep_bytes: 6060c744243c66d58400ff742408e859
timestamp: 2022-05-05 12:52:29

Version Info:

CompanyName: Installer for Squirrel
FileDescription: Installer for Squirrel-based applications
FileVersion: 6.85.1.77
InternalName: Installer Setup.exe
LegalCopyright: Copyright 2018-2022 based applications
ProductName: Squirrel-based application
ProductVersion: 6.85.1.77
Translation: 0x0012 0x03b5

Malware.AI.3448113302 also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 99)
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.8adc0f
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
RisingTrojan.Generic@AI.91 (RDMK:cmRtazrs+nVmFbLtFUv4ROb90UBH)
F-SecureTrojan.TR/Black.Gen2
FireEyeGeneric.mg.2796192ec00b9fe3
SophosMal/VMProtBad-A
AviraTR/Black.Gen2
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
MalwarebytesMalware.AI.3448113302
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34638.5D0@aGfXL7gP
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.3448113302?

Malware.AI.3448113302 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment