Malware

About “Malware.AI.3931740901” infection

Malware Removal

The Malware.AI.3931740901 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3931740901 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings

How to determine Malware.AI.3931740901?


File Info:

name: 4B59423DFB7628219793.mlw
path: /opt/CAPEv2/storage/binaries/652009b72dafd7da3bc3c7cd6f13411b0cbe9740f6ec362a6b9cba14f425ccc6
crc32: 4C4A6A8C
md5: 4b59423dfb76282197936a7a8db4541f
sha1: 796b7a67b66bba31d6222280f410edc54ea0f0d2
sha256: 652009b72dafd7da3bc3c7cd6f13411b0cbe9740f6ec362a6b9cba14f425ccc6
sha512: f4bc92b26df200c6cd918fb1608005ed4a1a1252c58a66e1fcc5461da4bd9d3cbd5b7fe713e4ca89e8c74e3be40f3b8915490de2f3979725feda2e1e668f2906
ssdeep: 192:9Sa8tcaAWyRxmxLjOB2Gth7gwGaHyM2EYHes/6Xh0YZQoRv5ZT3aXSJKi:9MOWy/mxLSnh71GPEUeCYh3Zrn93aXe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135B21857BA88F073C5108A34E25B5A27371F883181BEDE2FF7781A4866B5403A3F2706
sha3_384: 27cfab88c769e8468697dbb34568d7b4e6dd7173379254b191c8316a03751bf0502a9b08ff19fb04a343ef79005b4acd
ep_bytes: 558d6c248881ec74060000535657ff15
timestamp: 2005-02-16 21:40:47

Version Info:

0: [No Data]

Malware.AI.3931740901 also known as:

LionicTrojan.Win32.Small.l7pO
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.32974
MicroWorld-eScanGen:Trojan.Downloader.biY@a80fxh
FireEyeGeneric.mg.4b59423dfb762821
CAT-QuickHealTrojanDownloader.Tearsp.AA2
ALYacGen:Trojan.Downloader.biY@a80fxh
CylanceUnsafe
ZillyaDownloader.Agent.Win32.87965
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 000069a61 )
AlibabaTrojanDownloader:Win32/DLOADER.51db6adb
K7GWTrojan-Downloader ( 000069a61 )
Cybereasonmalicious.dfb762
BitDefenderThetaAI:Packer.374A41C61D
VirITTrojan.Win32.Agent2.BUWO
CyrenW32/KeyIso.A2.gen!Eldorado
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Agent.NPK
TrendMicro-HouseCallTROJ_DLOADER.PBG
ClamAVWin.Downloader.118002-1
KasperskyTrojan-Downloader.Win32.Agent.jy
BitDefenderGen:Trojan.Downloader.biY@a80fxh
NANO-AntivirusTrojan.Win32.Agent.diber
ViRobotTrojan.Win32.A.Downloader.22962
AvastWin32:Small-HFE [Trj]
RisingTrojan.DL.Agent.kx (CLOUD)
Ad-AwareGen:Trojan.Downloader.biY@a80fxh
EmsisoftGen:Trojan.Downloader.biY@a80fxh (B)
ComodoTrojWare.Win32.TrojanDownloader.Agent.NPK@1xok
BaiduWin32.Trojan-Downloader.Agent.ii
VIPREBehavesLike.Win32.Malware.bsm (vs)
TrendMicroTROJ_DLOADER.PBG
McAfee-GW-EditionBehavesLike.Win32.Generic.mt
SophosML/PE-A + Troj/Tear-C
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.eoa
AviraTR/Dldr.Small.RN.4
Antiy-AVLTrojan/Generic.ASMalwS.11275
KingsoftWin32.Heur.KVMH017.a.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataWin32.Trojan-Downloader.Generic.0HUJ20
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Small.R5459
Acronissuspicious
McAfeeDownloader-CMP
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Agent
MalwarebytesMalware.AI.3931740901
APEXMalicious
TencentMalware.Win32.Gencirc.10b3cc33
MaxSecureDownloader.W32.Small.RN
FortinetW32/Agent.FW!tr.dldr
AVGWin32:Small-HFE [Trj]
PandaBck/Unilink.B
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.3931740901?

Malware.AI.3931740901 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment