Malware

Malware.AI.3961694836 malicious file

Malware Removal

The Malware.AI.3961694836 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3961694836 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Harvests cookies for information gathering

How to determine Malware.AI.3961694836?


File Info:

name: EAB3447EFC46AE937C13.mlw
path: /opt/CAPEv2/storage/binaries/1a45e5b2384f788296353d5fe44004ec44c2effc3486b8522510da0f5f3965e7
crc32: 52CD7AFD
md5: eab3447efc46ae937c13ab334b84b28a
sha1: eda6375dffd328632fa9daeef99ac9a84c4c5e63
sha256: 1a45e5b2384f788296353d5fe44004ec44c2effc3486b8522510da0f5f3965e7
sha512: fe0d82dd1b90e56af76fcfe5fc867e440a5c2165efba14737dbe3f9115ae2f6762ca1fdeb32867e159015024128484034f4791c2dfb85c256e61505ed0e0d568
ssdeep: 3072:7DFfHgTWmCRkGbKGLeNTBf1y96DC57GyqcTezkk+LEoCoOL+p2LJhFj:v5aWbksiNTBtyqmNqgeILLEoLX4LJhB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12C548DC0D29AC2B3FFA783B500F6167A51B2763B47B1648FC389657045872B2A63D1B7
sha3_384: 63dc6b7ad2b163f6c981a7e3a7fadc32334aceb73c889c03bf5bd97976261524512acc2bbb67324db959248c7b9c5484
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2018-02-01 20:18:05

Version Info:

FileVersion: 2.9.2.0
ProductVersion: 2.9.2.0
ProductName: R6 Downloader
OriginalFilename: R6 Downloader
InternalName: R6 Downloader
FileDescription: R6 Downloader
CompanyName: R6 Downloader
LegalTrademarks: R6 Downloader
LegalCopyright: R6 Downloader
PrivateBuild: R6 Downloader
SpecialBuild: R6 Downloader
Comments: R6 Downloader
Translation: 0x0000 0x04e4

Malware.AI.3961694836 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47404468
FireEyeGeneric.mg.eab3447efc46ae93
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
BitDefenderThetaGen:NN.ZexaF.34114.ru0@a8ztZ6d
CyrenW32/Delf.MV.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PLF21
BitDefenderTrojan.GenericKD.47404468
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47404468
EmsisoftTrojan.GenericKD.47404468 (B)
TrendMicroTROJ_GEN.R002C0PLF21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosGeneric ML PUA (PUA)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.47404468
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4352097
ALYacTrojan.GenericKD.47404468
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3961694836
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaPUP/Generic
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3961694836?

Malware.AI.3961694836 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment