Malware

Malware.AI.3540153452 (file analysis)

Malware Removal

The Malware.AI.3540153452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3540153452 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Suspicious use of certutil was detected
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3540153452?


File Info:

name: 678EF4D94D9E422E15AE.mlw
path: /opt/CAPEv2/storage/binaries/7c81865b4ec4a6e308a7bf52e3bbef735fd8428928f13db5baa120c1a0b97eb1
crc32: DEA101D7
md5: 678ef4d94d9e422e15ae62d81b953a81
sha1: a4e9cfce99659c46b648d29404527a97a987aea0
sha256: 7c81865b4ec4a6e308a7bf52e3bbef735fd8428928f13db5baa120c1a0b97eb1
sha512: 5d86074c1e10958dbb84c86605e457fedcb4101b39362c52a7a16c0c25d843496b8b07acec29f2f15169f13aaa1d857036a2e63bbfbc213f2575334b5a2aa3d7
ssdeep: 1536:9EiBwAw/cGYQi1y2QNAx1FcLD12Qs7yGVd7U4nouy8ttsc3t1:bB9wUGYQN2XD6Udtouttfd1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T169330226E68D9C90C013E0350FC2A40B462ECA486DA5CB575DFC326B7ED87A4AC7D1F9
sha3_384: 0b08c7ebd11cdfaf7568c7b19b18798994db3a7f191a9b6925b1f6c269a0d887ebf99329144762937b24e92e1927b110
ep_bytes: 60be152041008dbeebeffeff5789e58d
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Malware.AI.3540153452 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Cert.Downloader.1.F88BE76F
FireEyeGeneric.mg.678ef4d94d9e422e
CAT-QuickHealTrojan.GenericPMF.S1998149
ALYacDropped:Generic.Cert.Downloader.1.F88BE76F
CylanceUnsafe
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.94d9e4
BitDefenderThetaGen:NN.ZexaF.34182.dmGfauD@avi
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Agen-7532797-0
KasperskyVHO:Trojan-Downloader.Win32.Agent.gen
BitDefenderDropped:Generic.Cert.Downloader.1.F88BE76F
EmsisoftDropped:Generic.Cert.Downloader.1.F88BE76F (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Inject
Antiy-AVLTrojan/Generic.ASMalwS.2B9E7F9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmVHO:Trojan-Downloader.Win32.Agent.gen
GDataDropped:Generic.Cert.Downloader.1.F88BE76F
CynetMalicious (score: 100)
MAXmalware (ai score=86)
MalwarebytesMalware.AI.3540153452
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_87%
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3540153452?

Malware.AI.3540153452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment