Malware

Malware.AI.3609685887 malicious file

Malware Removal

The Malware.AI.3609685887 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3609685887 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Malware.AI.3609685887?


File Info:

name: 51BFEE62D14F67A0FE0F.mlw
path: /opt/CAPEv2/storage/binaries/1b9bc21fc01927de58f9ac3c0765a764ca9ed2ee880ca424a58853ae42637c47
crc32: 26332223
md5: 51bfee62d14f67a0fe0fe1d417e2c095
sha1: aadcf36c246aaa875bec9b6ee21eb0f5c6b881e9
sha256: 1b9bc21fc01927de58f9ac3c0765a764ca9ed2ee880ca424a58853ae42637c47
sha512: 2df6790b6e0b77a2118b168ceb8a790aba7f5e4a598d5fc0546a35b1448f32c620ccba6246514cfc91059f72b7bc25a266f2b14e7410618d8880270ced2a5bc0
ssdeep: 49152:1yJLJh3XFEhWMQQcEJql7D6e5oCAeWZH64pLl17vP797d5z:UJHXFQWMQ7EkxD6e5oeWZH6Ml17vP7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193F59F2377958476D2531331180DA739C1FFAEB02A30AB6F67C8271E7A705C2D6366A7
sha3_384: 5c44f863475c12d99e8031e4b14796c20504d6ab529c8d803ed22b1f560afe148c951cf1d25ddf95476b934efcac7375
ep_bytes: e8f0110000e97afeffffcccccccc518d
timestamp: 2019-12-06 07:41:32

Version Info:

0: [No Data]

Malware.AI.3609685887 also known as:

BkavW32.Common.D6D70765
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.708797
FireEyeGen:Variant.Graftor.708797
SkyhighBehavesLike.Win32.Corrupt.wh
McAfeeArtemis!51BFEE62D14F
Cylanceunsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.c246aa
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Graftor.708797
AvastWin32:Malware-gen
SophosMal/Generic-S
VIPREGen:Variant.Graftor.708797
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.708797 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.708797
VaristW32/ABRisk.KTYR-5588
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Graftor.DAD0BD
MicrosoftTrojan:Win32/Occamy.C1B
GoogleDetected
AhnLab-V3PUP/Win32.Generic.R349274
BitDefenderThetaGen:NN.ZexaF.36608.qxW@aKKP8Wbj
ALYacGen:Variant.Graftor.708797
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3609685887
TrendMicro-HouseCallTROJ_GEN.R002H09I723
RisingTrojan.Occamy!8.F1CD (CLOUD)
MaxSecureTrojan.Malware.74835737.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Malware.AI.3609685887?

Malware.AI.3609685887 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment