Malware

Malware.AI.3771559112 information

Malware Removal

The Malware.AI.3771559112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3771559112 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3771559112?


File Info:

name: 6716F7A0E6F96617C9BA.mlw
path: /opt/CAPEv2/storage/binaries/6a6ecb6d053704d8b35a5155bab5ae98ab4febd959ccc74c57c3e5f472d9cdbf
crc32: 22AC0DE2
md5: 6716f7a0e6f96617c9ba4b47ff9f41eb
sha1: 27d6171a6bcba56b8abb1580103ba04089a7de27
sha256: 6a6ecb6d053704d8b35a5155bab5ae98ab4febd959ccc74c57c3e5f472d9cdbf
sha512: 04d41e73b0b8095c7fc2f59b52b704640f3316a782b52944691891f835c88750bc6a04dafbac327989a0e889ef1f994a53e6ccc8a95be9b49de6cbac0a413683
ssdeep: 98304:uG0YY8v3LT2D6X2TLGnJ1uBFQk+93x/Pzye5:pz//2DGOfBFr+9BjyG
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1B2F533B88CDD9A60D8DB77709B3B1E0B898AEE086A53C5065B705FBF14FE14354B049B
sha3_384: d31d7127ce1fdaf89f9a219b156d802e50edf25ee39e063c616dc19160c1cbc318b72bacdae29a088ed7bf04186a661d
ep_bytes: 53565755488d35aa8accff488dbedb8f
timestamp: 2018-02-01 19:43:24

Version Info:

0: [No Data]

Malware.AI.3771559112 also known as:

LionicTrojan.Win32.Razy.4!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
McAfeeArtemis!6716F7A0E6F9
CylanceUnsafe
SangforTrojan.Win32.Ponteiro.kw
K7AntiVirusSpyware ( 00563ab81 )
K7GWSpyware ( 00563ab81 )
Cybereasonmalicious.0e6f96
VirITTrojan.Win32.KillAll.FK
CyrenW64/MSIL_Agent.CHD.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Spy.Casbaneiro.BE
ClamAVWin.Malware.Killall-6913734-0
KasperskyTrojan-Banker.Win32.Ponteiro.kw
AlibabaTrojanBanker:Win32/Ponteiro.a0fec77b
APEXMalicious
RisingSpyware.Casbaneiro!8.F962 (CLOUD)
F-SecureTrojan.TR/Spy.Casbaneiro.yhtwh
DrWebTrojan.KillAll.140
McAfee-GW-EditionBehavesLike.Win64.Generic.wc
FireEyeGeneric.mg.6716f7a0e6f96617
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bzgyb
AviraTR/Spy.Casbaneiro.yhtwh
Antiy-AVLTrojan/Generic.ASMalwS.3517293
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3PUP/Win32.InstallMonster.C2844192
Acronissuspicious
VBA32Trojan.KillAll
MalwarebytesMalware.AI.3771559112
IkarusTrojan.Diztakun
FortinetW64/Agent.B136!tr
AVGFileRepMetagen [Trj]
AvastFileRepMetagen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3771559112?

Malware.AI.3771559112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment