Malware

About “Malware.AI.360844653” infection

Malware Removal

The Malware.AI.360844653 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.360844653 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese
  • Installs itself for autorun at Windows startup

Related domains:

abrilprorock2018.webcindario.com
hoteldobook2018.webcindario.com

How to determine Malware.AI.360844653?


File Info:

crc32: 60560745
md5: 0b986b68cdc7671bac2cb0d0671093a1
name: 0B986B68CDC7671BAC2CB0D0671093A1.mlw
sha1: cbbb2979016289f0cbed04160ac01625786902ec
sha256: 501f95305bcb72870186d9be29aecdbc9a8f0e5ef51c59e2c7c8ee78e18b7cad
sha512: 5eb0590ac675feb603f1b69172794d1e064e85ca1c147ea20499c514dc3eda846fa1ea05ba15fe7a029d84f8b548fcf92c58f3faf3e772d81b5d507365470cf1
ssdeep: 49152:RyS/tIAtM0XXBQEZ2Ch84TpkxuYQlYGfe1zKBh1Y8M7zAv5oR6Ef:DtRXBB4Ch8xuYQeQ8KBPdhoR6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.360844653 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00565e681 )
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
CAT-QuickHealTrojan.BestaFera
ALYacGen:Variant.Jacard.141311
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanSpy:Win32/Banker.c7f6863c
K7GWSpyware ( 00565e681 )
Cybereasonmalicious.8cdc76
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.AEKA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderGen:Variant.Jacard.141311
NANO-AntivirusTrojan.Win32.BestaFera.ifuvek
MicroWorld-eScanGen:Variant.Jacard.141311
TencentWin32.Trojan-banker.Bestafera.Hpg
Ad-AwareGen:Variant.Jacard.141311
SophosMal/Generic-S
F-SecureBackdoor.BDS/Hupigon.Gen
BitDefenderThetaAI:Packer.CC0BAFE919
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0GLS20
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.0b986b68cdc7671b
EmsisoftGen:Variant.Jacard.141311 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.BestaFera.fsm
AviraBDS/Hupigon.Gen
eGambitUnsafe.AI_Score_65%
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Jacard.D227FF
ZoneAlarmHEUR:Trojan-Banker.Win32.BestaFera.gen
GDataGen:Variant.Jacard.141311
AhnLab-V3Malware/Gen.Generic.C2921650
McAfeeArtemis!0B986B68CDC7
MAXmalware (ai score=84)
VBA32BScope.TrojanBanker.BestaFera
MalwarebytesMalware.AI.360844653
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R067C0GLS20
RisingSpyware.Banker!8.8D (TFE:4:MEYmCR8I0ZC)
YandexTrojanSpy.Banker!iBdt6dSNl+0
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.73698876.susgen
FortinetW32/BestaFera.AEKA!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Backdoor.Hupigon.HgIASOYA

How to remove Malware.AI.360844653?

Malware.AI.360844653 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment