Malware

Malware.AI.477396769 (file analysis)

Malware Removal

The Malware.AI.477396769 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.477396769 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Malware.AI.477396769?


File Info:

name: FF554989848F580D1DEE.mlw
path: /opt/CAPEv2/storage/binaries/d9e6d0755d2f41fa983f948fd8ddaab83c5deaf4782872eb8f5850cc69a3f63b
crc32: 7C59C0B8
md5: ff554989848f580d1deec4e7118deece
sha1: 4882437153c50f498759a892fc2b994e89040766
sha256: d9e6d0755d2f41fa983f948fd8ddaab83c5deaf4782872eb8f5850cc69a3f63b
sha512: 4f0c7967d85b384fa1b155b8f3165f2901def187921588695e1be06f62bab9772f923612247ef59ca6cf963761e7843afedbde3e1a5323a75f9ad2b3cb6c0a67
ssdeep: 384:b2AsyDTIWwt2JdtTsGH1ARxruGO8o+4tdmuQc1PbJig:y+DT/jTsGVNQMfJig
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139A26B6435E31C12EA70A470C7F3D26059BDFC61AF55A6FFBAC0386868379C56A21A1C
sha3_384: 23d747764bbad75e6b7730454848d3f85544708563ad3f228bf7c56d874b5cc4cc1beceb0887c641eecea11ef9a2921e
ep_bytes: 8bec892d58504000e809120000688711
timestamp: 2013-09-04 13:17:35

Version Info:

0: [No Data]

Malware.AI.477396769 also known as:

BkavW32.FamVT.GeND.Trojan
MicroWorld-eScanTrojan.GenericKD.1236448
ClamAVWin.Downloader.Upatre-5744092-0
FireEyeGeneric.mg.ff554989848f580d
CAT-QuickHealTrojanDownloader.Upatre.A5
McAfeePWSZbot-FFA!FF554989848F
CylanceUnsafe
VIPRETrojan.GenericKD.1236448
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9848f5
BaiduWin32.Trojan-Downloader.Small.ce
VirITTrojan.Win32.Zyx.XH
CyrenW32/Trojan.JQOX-2231
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.PRL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Bublik.beae
BitDefenderTrojan.GenericKD.1236448
NANO-AntivirusTrojan.Win32.Bublik.codrww
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b2f792
Ad-AwareTrojan.GenericKD.1236448
SophosML/PE-A + Mal/EncPk-MP
ComodoTrojWare.Win32.TrojanDownloader.Bublik.AKG@5q4fvn
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Bublik.Win32.11868
TrendMicroTROJ_UPATRE.CK
McAfee-GW-EditionPWSZbot-FFA!FF554989848F
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.1236448 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.1236448
JiangminTrojan/Bublik.fww
AviraTR/AD.Yarwi.obmwk
Antiy-AVLTrojan/Generic.ASBOL.C6E4
MicrosoftTrojanDownloader:Win32/Upatre.A
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R81603
VBA32Trojan.FakePdf.5817
ALYacTrojan.GenericKD.1236448
MAXmalware (ai score=83)
MalwarebytesMalware.AI.477396769
TrendMicro-HouseCallTROJ_UPATRE.CK
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!kjoUD9cd4AU
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.BEUK!tr
BitDefenderThetaGen:NN.ZexaF.34592.bqX@aeCPzMbi
AVGWin32:Malware-gen
PandaTrj/Downloader.WKY
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.477396769?

Malware.AI.477396769 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment