Malware

What is “Malware.AI.3897408886”?

Malware Removal

The Malware.AI.3897408886 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3897408886 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Deletes executed files from disk
  • Creates known SpyNet mutexes and/or registry changes.
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3897408886?


File Info:

name: 09438242F1CAFCF14281.mlw
path: /opt/CAPEv2/storage/binaries/21eb82052709427e09ab024bedeaa5cd036867a6107f8e4aeb975943917daf66
crc32: 5CC9FD13
md5: 09438242f1cafcf142811c050570ebb6
sha1: 15a0d8ade9aa846d640022cdc73171b32a978ded
sha256: 21eb82052709427e09ab024bedeaa5cd036867a6107f8e4aeb975943917daf66
sha512: dee3134036cd465ae21a23c4407d9a14f9807ea2eee10ee0f195e899feff3aaddece3faf26dbb9610141df320b957e51e1147a31283291450fd707b9664bf1d0
ssdeep: 12288:IlgYoSqSNJ/Jj0UHsL/OW2lJimtlVYNC/8La:2gnSNb0EsL/OW2lsm/C3a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEB42342761AFF38C36203385949F5B42519FAB076E82F9BF0D5BB07DF920A5B426718
sha3_384: 904bb78a94cc45ffe35289b8ce3275532d91544b37ffdc953706a4849d4aed79d5b74f6c5a9098cb63e9e953f3dae12a
ep_bytes: 61be005041008dbe00c0feff5789e58d
timestamp: 2012-01-21 00:57:17

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.4.3.2367
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: January 21, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.4.3.2367
Translation: 0x0000 0x04b0

Malware.AI.3897408886 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Azbreg.miLK
MicroWorld-eScanTrojan.Azberg.B
ALYacTrojan.Azberg.B
MalwarebytesMalware.AI.3897408886
VIPRETrojan.Azberg.B
SangforBackdoor.Win32.Azbreg.Vqdj
AlibabaBackdoor:Win32/Azbreg.eefb379f
Cybereasonmalicious.2f1caf
VirITTrojan.Win32.Generic.ACFM
SymantecTrojan.Dropper
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.MTXQRVE
APEXMalicious
AvastWin32:Dropper-LPW [Drp]
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.Azbreg.asq
BitDefenderTrojan.Azberg.B
NANO-AntivirusTrojan.Win32.Azbreg.dmpakg
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
TencentMalware.Win32.Gencirc.10b475fa
TACHYONBackdoor/W32.Azbreg.531726
EmsisoftTrojan.Azberg.B (B)
F-SecureTrojan.TR/Drop.Agent.LPJ
DrWebTrojan.PWS.Siggen.36594
ZillyaBackdoor.Azbreg.Win32.4562
TrendMicroTSPY_AZBERG.SM-R12
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
FireEyeGeneric.mg.09438242f1cafcf1
SophosMal/Generic-S
GDataTrojan.Azberg.B
AviraTR/Drop.Agent.LPJ
XcitiumBackdoor.Win32.Azbreg.ASQ@4pmhzu
ArcabitTrojan.Azberg.B
ZoneAlarmBackdoor.Win32.Azbreg.asq
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Backdoor/Win32.Azbreg.R29412
McAfeeArtemis!09438242F1CA
MAXmalware (ai score=85)
VBA32Trojan.Tiggre
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_AZBERG.SM-R12
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.4201350.susgen
FortinetW32/Azbreg.ASQ!tr
AVGWin32:Dropper-LPW [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3897408886?

Malware.AI.3897408886 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment