Malware

Malware.AI.3665560310 (file analysis)

Malware Removal

The Malware.AI.3665560310 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3665560310 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3665560310?


File Info:

name: F2F0AA6BA88C299DD5FA.mlw
path: /opt/CAPEv2/storage/binaries/aabe4577b982728640219ea9a7f4a652b691d0ad60490aade367fba3789f9952
crc32: D96703AB
md5: f2f0aa6ba88c299dd5fa9d4da785e7d4
sha1: b5b017b0e1b72f0d67a5b6d8875c4557bbb57ad7
sha256: aabe4577b982728640219ea9a7f4a652b691d0ad60490aade367fba3789f9952
sha512: 8eae3964b00117b314cb1a9c6173799dff6edb34b0cb2f53d8149d8c998f47805b9c8fe113b55b260f0ddf8a7a4bee76fd52578baaf95c4147f31eac539bc858
ssdeep: 49152:GBuZrEUw1OrWv4AbwCXiulq7Sq6g6zSezlS/dS:QkLtiv4uboSzXz2/E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2C5E03FB268653EC5AE1BB245B39210997B7F61B81B8C1E47F0280CCF364615E3B659
sha3_384: 92cc22c1d95268ff6b071668393437d3785ecdc0f3f145c99c65eed65cce6430a084539ffb93b98e8e15748a759bd8c0
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ankara
FileDescription: Ankara serveur Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Ankara serveur
ProductVersion: 2.0.0
Translation: 0x0000 0x04b0

Malware.AI.3665560310 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.Generic.33706598
ALYacTrojan.Generic.33706598
Cylanceunsafe
VIPRETrojan.Generic.33706598
SangforTrojan.Win32.Agent.Vcok
K7AntiVirusTrojan ( 0056e5201 )
K7GWTrojan ( 0056e5201 )
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.33706598
AvastWin32:Malware-gen
RisingTrojan.Undefined!8.1327C (CLOUD)
EmsisoftTrojan.Generic.33706598 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
Trapminesuspicious.low.ml.score
FireEyeTrojan.Generic.33706598
SophosGeneric Reputation PUA (PUA)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2025266
GDataTrojan.Generic.33706598
AhnLab-V3Trojan/Win.Generic.C5426156
McAfeeArtemis!F2F0AA6BA88C
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3665560310
TrendMicro-HouseCallTROJ_GEN.R03BH09EE23
MaxSecureTrojan.Malware.207425671.susgen
FortinetW32/NDAoF.EHUZRO!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Malware.AI.3665560310?

Malware.AI.3665560310 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment