Malware

Malware.AI.389107300 (file analysis)

Malware Removal

The Malware.AI.389107300 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.389107300 virus can do?

  • Unconventionial language used in binary resources: Xhosa
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.389107300?


File Info:

name: C0556DDFBDDDD829020C.mlw
path: /opt/CAPEv2/storage/binaries/a8a827f8d7cdcc3e68908da21c9a87b5ba39c53596b18c4775bdfe1d09fe14b3
crc32: 2A758CFC
md5: c0556ddfbdddd829020c7e8de2f8846d
sha1: 329c0144a1dbbf0f9c4d6747920d21211757b25b
sha256: a8a827f8d7cdcc3e68908da21c9a87b5ba39c53596b18c4775bdfe1d09fe14b3
sha512: 5a98e9fe1f66a6a60e657589b88f902c2f78488b17a4128dbc93da6a047cb83b600066cec41750a576b16f315af22d71ff1f25241bbd359c41f3862cef92fab1
ssdeep: 3072:WeBTMAL+qV2kG084v5Y9Pjo06pq4chk9UeBHeiBnrn:WeBTtLxV2kG0wjsp5ebhilrn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C44BF217D80C031C49E05788856CFF18B7EB831EA6185677779EB6E5E203E16E2A35F
sha3_384: dfb683bdc721c79b99a578c605668bf06683c6f39952fae8c0bb8fc2793165651644a7498ef5f7fdb677b0f746806714
ep_bytes: e879480000e979feffff832564d74300
timestamp: 2020-08-02 05:31:06

Version Info:

0: [No Data]

Malware.AI.389107300 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.SmartFortress.lEDV
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83012
CAT-QuickHealTrojan.AgentPMF.S26388988
ALYacTrojan.GenericKDZ.83012
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053d5971 )
AlibabaRansom:Win32/StopCrypt.4773caf9
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.4a1dbb
CyrenW32/Qbot.FK.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HOCK
TrendMicro-HouseCallRansom_StopCrypt.R002C0DB822
Paloaltogeneric.ml
BitDefenderTrojan.GenericKDZ.83012
APEXMalicious
RisingExploit.ShellCode!8.2A (CLOUD)
Ad-AwareTrojan.GenericKDZ.83012
SophosML/PE-A
DrWebTrojan.DownLoader44.35181
ZillyaTrojan.Kryptik.Win32.3681091
TrendMicroRansom_StopCrypt.R002C0DB822
McAfee-GW-EditionLockbit-FSWW!C0556DDFBDDD
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.c0556ddfbdddd829
EmsisoftTrojan.GenericKDZ.83012 (B)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.PSE.14QH1HG
JiangminExploit.ShellCode.gkk
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.351476A
GridinsoftRansom.Win32.STOP.sa
ArcabitTrojan.Generic.D14444
MicrosoftRansom:Win32/StopCrypt.PAR!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R470788
McAfeeLockbit-FSWW!C0556DDFBDDD
VBA32TrojanRansom.Convagent
MalwarebytesMalware.AI.389107300
AvastWin32:AceCrypter-C [Cryp]
TencentTrojan-ransom.Win32.Stop.16000284
SentinelOneStatic AI – Malicious PE
FortinetW32/GenericKDZ.6DF1!tr
AVGWin32:AceCrypter-C [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.389107300?

Malware.AI.389107300 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment