Malware

Malware.AI.3912967089 information

Malware Removal

The Malware.AI.3912967089 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3912967089 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempted to write directly to a physical drive
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.3912967089?


File Info:

name: 124E08F783B7CF8BD51C.mlw
path: /opt/CAPEv2/storage/binaries/045fcfa284311e722796efd21b11d201d21194ca951233335a36356b25d56de4
crc32: 435C62C3
md5: 124e08f783b7cf8bd51cc917e95b3292
sha1: 6306389f018ad1e441d2caa6778d3d159bc18465
sha256: 045fcfa284311e722796efd21b11d201d21194ca951233335a36356b25d56de4
sha512: bdca27e79182b5cd26f28e46af72540b630571b2a2e81e3f97d91cee3c45fd6be0043ba2862a17061be881126c78f37121f1299b437e291043d62de32966ad7a
ssdeep: 24576:pdzoBOwJbHnv9BV40OWcpNfQrlofX+FwxIRmTiKuHxW:puvc7xDxdTiKuHx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T145257E239320C8D2E16815F262B9073C7DB8A3611C758B67EFD48DB19D60AF29F57A0D
sha3_384: b535f14031c3daa8914abf8a9d4b7dfe36cf0d9dfed514e01861062ee8ff9870eb29e9ddf301f7af6f3bedc77e2c18ba
ep_bytes: e8cbf20100e8fff0010033c0c3909090
timestamp: 2022-05-04 22:14:33

Version Info:

0: [No Data]

Malware.AI.3912967089 also known as:

BkavW32.AIDetect.malware1
DrWebDLOADER.Trojan
FireEyeGeneric.mg.124e08f783b7cf8b
MalwarebytesMalware.AI.3912967089
K7AntiVirusTrojan ( 005328801 )
K7GWTrojan ( 005328801 )
Cybereasonmalicious.783b7c
BitDefenderThetaGen:NN.ZexaF.34638.9qW@a0z@Mxjb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
ClamAVWin.Dropper.Tiggre-9845940-0
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Behav-027
IkarusAdWare.Win32.BlackMoon
AviraTR/Downloader.Gen2
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C5116038
Acronissuspicious
McAfeeGenericRXJC-QQ!124E08F783B7
VBA32BScope.Trojan.Miner
CylanceUnsafe
APEXMalicious
RisingTrojan.Generic@AI.77 (RDMK:cmRtazqT2x8FtBgLxJ0aNkUhY9tO)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.WP!tr
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.3912967089?

Malware.AI.3912967089 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment