Malware

Malware.AI.3878148564 (file analysis)

Malware Removal

The Malware.AI.3878148564 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3878148564 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering

How to determine Malware.AI.3878148564?


File Info:

name: 4A29CA40A5711644D81E.mlw
path: /opt/CAPEv2/storage/binaries/7231f23510ca5cadaa2cd403005e01ed365ba67079e510be08134c6b0d108699
crc32: 882331B0
md5: 4a29ca40a5711644d81e10dc7caf6e5f
sha1: 6ff7623f47c94d16b69a80f837bafe3d9adb4bfa
sha256: 7231f23510ca5cadaa2cd403005e01ed365ba67079e510be08134c6b0d108699
sha512: d2d5b943708cee3c2dd5a06ba3f1ff3b019149dcec6048fb2434032ef7ae3d4abe0a8cfb64f9a055221bec1d321edac079eeea7d268e8a7e9006410281e99f1e
ssdeep: 12288:9crNS33L10QdrXP/X+tGfnwqyi3g1I6c8W+S7Dq:ANA3R5drXPrfce6TVS/q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138A4E011B7D284B2E53319365939AB21697C7D301E35CEAFB3D86E2DCE30191A225B73
sha3_384: 38a2ff9092286e0f1484418fa8a8eadb9010181749e574a33a62428f6000041f80f059682b120b8e0b13d501733d8655
ep_bytes: e85a040000e98efeffff3b0dc8a14300
timestamp: 2019-04-27 20:03:27

Version Info:

0: [No Data]

Malware.AI.3878148564 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.4a29ca40a5711644
CAT-QuickHealTrojan.GenericPMF.S7246987
SkyhighBehavesLike.Win32.Generic.gc
McAfeeRDN/Generic.dx
Cylanceunsafe
APEXMalicious
CynetMalicious (score: 100)
SophosGeneric ML PUA (PUA)
Kingsoftmalware.kb.a.935
AhnLab-V3Malware/Win.Generic.C5128189
MalwarebytesMalware.AI.3878148564
TrendMicro-HouseCallTROJ_GEN.R002H06K823
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.3878148564?

Malware.AI.3878148564 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment