Malware

Malware.AI.38022306 (file analysis)

Malware Removal

The Malware.AI.38022306 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.38022306 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.38022306?


File Info:

name: 4F4C087C340EC164411A.mlw
path: /opt/CAPEv2/storage/binaries/552474dca5e460be71b03b1553193d3705aca2eb838145551b72576ce11d5390
crc32: BD7BB954
md5: 4f4c087c340ec164411a34c5bacec6db
sha1: 4f27b45d04ae1627982b5154a739fcc9a8dfa697
sha256: 552474dca5e460be71b03b1553193d3705aca2eb838145551b72576ce11d5390
sha512: 1dfbb519d8f72dd3b50a24c9a2273a5fccb020c1289157b4ef18d14a9ebbf2e2798904aa6a2b268f7f5bc44f95b4512295e52a454d86730e5acda0075d6beffc
ssdeep: 6144:XC8Ty1tI+0tjU6KvBTx+H41K5Syuw5eUQcEjGUXdmd14rls:XNsN0NU6KvBTMY1Vyuw7Qrqkdc1l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1275423762DBE11B9C02F5D3550C63EA07D8682E408998653CBF6FF6EE4944AA1F2311B
sha3_384: 55b1e2a2f2ca0d2fc6f86d2cacc5a4d1dd0f092c8dd0b6ca01717948b20c16e7a7612f49daafead2272266bec7280fea
ep_bytes: 60be001049008dbe0000f7ff5783cdff
timestamp: 2010-08-29 00:48:43

Version Info:

0: [No Data]

Malware.AI.38022306 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Click2.1642
MicroWorld-eScanGen:Variant.Graftor.Elzob.11247
FireEyeGeneric.mg.4f4c087c340ec164
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bca301 )
K7GWSpyware ( 004bca301 )
Cybereasonmalicious.c340ec
BitDefenderThetaGen:NN.ZexaF.34294.smHfa0QPcro
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Agent.NVD
TrendMicro-HouseCallTSPY_BABMOTE_CD100231.RDXN
KasperskyTrojan-Dropper.Win32.Dorgam.agp
BitDefenderGen:Variant.Graftor.Elzob.11247
NANO-AntivirusTrojan.Win32.Clicker.ddouvz
AvastWin32:Dh-A [Heur]
Ad-AwareGen:Variant.Graftor.Elzob.11247
SophosMal/Scar-G
BaiduWin32.Trojan-Spy.Agent.r
ZillyaTrojan.Scar.Win32.39170
TrendMicroTSPY_BABMOTE_CD100231.RDXN
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Graftor.Elzob.11247 (B)
IkarusTrojan-PWS.Win32.QQPass
JiangminTrojan/Generic.tdbx
eGambitUnsafe.AI_Score_100%
AviraTR/Taranis.4038
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.A.PSW-QQPass.802816[UPX]
GDataWin32.Trojan.PSE.TTYZPG
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.QQPass.C610863
Acronissuspicious
VBA32Trojan.Scar
ALYacGen:Variant.Graftor.Elzob.11247
MalwarebytesMalware.AI.38022306
APEXMalicious
RisingDropper.Win32.Fednu.af (CLASSIC)
YandexTrojan.GenAsa!DRckhPGF1To
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQPass.YZN!tr.pws
AVGWin32:Dh-A [Heur]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.38022306?

Malware.AI.38022306 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment