Malware

Malware.AI.3930585995 malicious file

Malware Removal

The Malware.AI.3930585995 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3930585995 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Malware.AI.3930585995?


File Info:

name: A71B5AA3D9EBAFF3EAD5.mlw
path: /opt/CAPEv2/storage/binaries/32dbf89ded4a703803b9626d1b82b073937dc79a4cbda5fc4ba3f1ada3f41566
crc32: 0ECD81C3
md5: a71b5aa3d9ebaff3ead5dfd3d8f49cfb
sha1: 268c9e6a44526e69f5077be27812a9284713536a
sha256: 32dbf89ded4a703803b9626d1b82b073937dc79a4cbda5fc4ba3f1ada3f41566
sha512: ea53e616188c55c6576154eb005ce2fdbfb7a8ebf254b8eace9abe1c9d2a287350149a6f83534fb63feac3e4086a215389be7ad3893a7f014e9fb9813f82a390
ssdeep: 12288:cetRwarT0vmVkbc7Qk0rJMSFFYqdC2GdPcE/1eIy7odFRcqz:PtCXmVYQdeU/v35
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB25AE657190E8B2C13B4378894BABE46425BF106B18ED8777E87D0E5FF8750B826387
sha3_384: 1b259221cacf93fb03ffca9a3155d7939064f3f00af41cdb1d70b2c498ae132d1a6980fe1b64fe5e4cf0bf7c330aaa10
ep_bytes: 558bec83c4f053b810d94800e84f91f7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.3930585995 also known as:

LionicTrojan.Win32.BestaFera.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.31245956
FireEyeTrojan.Generic.31245956
ALYacTrojan.Generic.31245956
CylanceUnsafe
K7AntiVirusTrojan ( 0058b35f1 )
AlibabaTrojanBanker:Win32/BestaFera.14014319
K7GWTrojan ( 0058b35f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EQQS
APEXMalicious
KasperskyHEUR:Trojan-Banker.Win32.BestaFera.gen
BitDefenderTrojan.Generic.31245956
AvastWin32:Trojan-gen
TencentWin32.Trojan-banker.Bestafera.Lknj
Ad-AwareTrojan.Generic.31245956
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PL821
McAfee-GW-EditionFareit-FCVN!A71B5AA3D9EB
EmsisoftTrojan.Generic.31245956 (B)
IkarusTrojan.Inject
GDataWin32.Trojan-Downloader.DBatLoader.BCDKR7
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D1DCC684
MicrosoftTrojan:Win32/Woreflint.A!cl
McAfeeFareit-FCVN!A71B5AA3D9EB
VBA32BScope.Backdoor.Androm
MalwarebytesMalware.AI.3930585995
TrendMicro-HouseCallTROJ_GEN.R002C0PL821
YandexTrojan.Igent.bW4tDJ.2
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/EQQS.FCVN!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Malware.AI.3930585995?

Malware.AI.3930585995 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment