Malware

Malware.AI.357269150 (file analysis)

Malware Removal

The Malware.AI.357269150 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.357269150 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.357269150?


File Info:

name: 7C07D4AE990B93E96B68.mlw
path: /opt/CAPEv2/storage/binaries/08ea94052e25d873b24324968b9427721fafc6afad4fe3b4537b0e6299f9537c
crc32: 01BE5C87
md5: 7c07d4ae990b93e96b688dabcf6940d6
sha1: f07c78fdc6df0cc30c0fb06659b2d861311a3618
sha256: 08ea94052e25d873b24324968b9427721fafc6afad4fe3b4537b0e6299f9537c
sha512: c981c98e842b0ba5e7b9c50f30bab370239b9c565e8c803de0b1f9787d267e1b1aa13d028ea1ec0bc697efeb878f094c7fa0aa161a4a7ebaf7556914b481c094
ssdeep: 24576:K/Z7SGKxUWS8iB0mMBwKXazAEh/+8bPn3Pc1QxoPR7K2CEDV:cZONxEBCwKXcAAn3c1sT2CW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF45F110ABED5713F6F74B7C6DF158A28972B911B92ACB89106B1A8C0D72791CC11B2F
sha3_384: 8eb48a98126f7c6fdbe84e0fd5bb7361e0974b4d674e54c91ff96034ef0f2de293f0b9bce63b2131a61f960923014c5b
ep_bytes: ff2500605a0024ea000000003feb751e
timestamp: 2049-03-21 00:41:01

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: I Antiban
FileVersion: 1.0.0.0
InternalName: I Antiban.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: I Antiban.exe
ProductName: I Antiban
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.357269150 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.730302
FireEyeGeneric.mg.7c07d4ae990b93e9
McAfeeArtemis!7C07D4AE990B
MalwarebytesMalware.AI.357269150
K7AntiVirusTrojan ( 00574e2d1 )
AlibabaPacked:MSIL/VMProtect.62fe097d
K7GWTrojan ( 00574e2d1 )
Cybereasonmalicious.e990b9
BitDefenderThetaGen:NN.ZemsilF.34062.mv0@ai64rbp
CyrenW32/MSIL_Troj.BKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
TrendMicro-HouseCallTROJ_GEN.R002H09KT21
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.Ursu.730302
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Ursu.730302
EmsisoftGen:Variant.Ursu.730302 (B)
IkarusTrojan.MSIL.Vmprotect
MaxSecureTrojan.Malware.300983.susgen
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.730302
CynetMalicious (score: 100)
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
FortinetRiskware/Application
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.357269150?

Malware.AI.357269150 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment