Malware

What is “Malware.AI.350019620”?

Malware Removal

The Malware.AI.350019620 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.350019620 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Malware.AI.350019620?


File Info:

name: 18F22B77487F4E91AD07.mlw
path: /opt/CAPEv2/storage/binaries/86389e2ab75a4121ad8d2dcc1bbe2ed0348a346241a50ce019bbf5d3edb3795b
crc32: 7885499F
md5: 18f22b77487f4e91ad07f939a284d66c
sha1: 066eba8bd8daf168888e1624c8ed8f39082bb03f
sha256: 86389e2ab75a4121ad8d2dcc1bbe2ed0348a346241a50ce019bbf5d3edb3795b
sha512: bd052da2c2b215d9d3698e04cfe819a746a0b2c33c9c90ccac5a60af048d5805c75355ad230fe0ae2550520c540f96b290093baee9bf11335aa89b13fe99f2dc
ssdeep: 1536:lEkRo2fTPMNkdLSPq0F8H+effMtFdIgv/u:lEkRo2zMNbPJF8BffoFdI/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3433A819BD88759ECFD1D300974A611133ABE6A6623DB1EBDCCF0552EB3381C9219B7
sha3_384: 713e1d103561dc48075e6a83c5a52593ce4f41c3d618945a28121de15fe57422b8b445d4c52dddded0315a8ba7e96ed6
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-04-17 09:24:30

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: Microsoft Office Word Document
FileVersion: 1.0.1.0
InternalName: securityScan.exe
LegalCopyright: Microsoft Office © 2015
OriginalFilename: securityScan.exe
ProductName: Microsoft Office
ProductVersion: 1.0.1.0
Assembly Version: 1.0.1.0

Malware.AI.350019620 also known as:

FireEyeGeneric.mg.18f22b77487f4e91
CAT-QuickHealTrojanAPT.MsoGen.A3
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bd8daf
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.ABV
APEXMalicious
CynetMalicious (score: 99)
AvastWin32:Malware-gen
Trapminemalicious.moderate.ml.score
SophosMal/Agent-ATK
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1204242
Antiy-AVLTrojan/Generic.ASMalwS.2D
MicrosoftBackdoor:Win32/Bladabindi!ml
GoogleDetected
BitDefenderThetaGen:NN.ZemsilF.34592.dq2@aavSMse
MalwarebytesMalware.AI.350019620
YandexTrojan.Agent!w14bNmpYCrQ
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.350019620?

Malware.AI.350019620 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment