Malware

Malware.AI.4195588339 (file analysis)

Malware Removal

The Malware.AI.4195588339 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.4195588339 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering

How to determine Malware.AI.4195588339?


File Info:

name: 67118D8A645888F63F8C.mlw
path: /opt/CAPEv2/storage/binaries/5431b37fce28a8ab190c0f4242dfc57a3e990a8471f5756e560c17c9e8e53018
crc32: B81CB7BB
md5: 67118d8a645888f63f8c7f977bfdd8ce
sha1: a570ad974438cb8cbbf2d981c92f5447f4a5f6ec
sha256: 5431b37fce28a8ab190c0f4242dfc57a3e990a8471f5756e560c17c9e8e53018
sha512: 9eee214963dbc2444aefeb007cfd3b8abf58d60fa18d4c9e888f0f6d67627bc4a9f5e7daaf4fa85defaef903fe33fb1f76a6b97036e4a5100f0c7d8327159959
ssdeep: 1536:XcZknpLRHuy96uaKh6lv6esnFZ9cGbL7o4busHBKaVD:XckZK4PV3oyusHBKaVD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11353029E60794F39CAE1A4782E5F67C6225FCC29C63B0E1182C148DBF62631D11CC732
sha3_384: aa13f4a96d00d60d806449cd2e3341e307d08ecb7fea03985b62d8dc71e2ceaa666614bdaf889c55f1e595318deec479
ep_bytes: 60be008042008dbe0090fdff5783cdff
timestamp: 2013-05-25 15:00:36

Version Info:

0: [No Data]

Malware.AI.4195588339 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Scar.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.9216403
ALYacTrojan.Generic.9216403
CylanceUnsafe
ZillyaTrojan.Scar.Win32.79793
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00035c011 )
AlibabaTrojan:Win32/Hupigon.7c72cd58
K7GWTrojan ( 00035c011 )
Cybereasonmalicious.a64588
BaiduWin32.Trojan.Agent.a
VirITTrojan.Win32.Generic.AAMW
CyrenW32/A-77a8ec0b!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.NXB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Scar-8432
KasperskyTrojan.Win32.Scar.hofr
BitDefenderTrojan.Generic.9216403
NANO-AntivirusTrojan.Win32.Scar.ebyndu
AvastWin32:Evo-gen [Trj]
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
Ad-AwareTrojan.Generic.9216403
SophosMal/Generic-S
ComodoMalware@#2xijdj87znp4h
DrWebTrojan.DownLoader9.29513
VIPRETrojan.Generic.9216403
TrendMicroTROJ_VB_FE2501EB.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.67118d8a645888f6
EmsisoftTrojan.Generic.9216403 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.9216403
JiangminTrojan/Scar.bbme
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.103
KingsoftWin32.Troj.Scar.ho.(kcloud)
ArcabitTrojan.Generic.D8CA193
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C25863
Acronissuspicious
McAfeeArtemis!67118D8A6458
VBA32Trojan.Scar
MalwarebytesMalware.AI.4195588339
TencentTrojan.Win32.VB.tqq
YandexTrojan.Scar!FarI0KqiOro
IkarusBackdoor.Win32.Hupigon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.NXB!tr
BitDefenderThetaAI:Packer.678F97FC20
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.4195588339?

Malware.AI.4195588339 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment