Malware

Malware.AI.484471131 (file analysis)

Malware Removal

The Malware.AI.484471131 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.484471131 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.484471131?


File Info:

name: 63E8E9EDCE369B8D5026.mlw
path: /opt/CAPEv2/storage/binaries/6fe2bee0d92fdb3938d61e40b368b6d102fdc08b38577bce3699159e11173371
crc32: 9FD4F9DC
md5: 63e8e9edce369b8d50262f196e59138f
sha1: 246fe4e28961c9d287bc40d8b29d67d32d4fd26c
sha256: 6fe2bee0d92fdb3938d61e40b368b6d102fdc08b38577bce3699159e11173371
sha512: 5443be011ce099b5c2edd5e42c51143260a422ccc3c357be6e1ac801c44f4050bf1f73b46bd70c92761450a8b0eea7504f970a2d74daf681112b0a3ae7561389
ssdeep: 96:mBJYtOvLGaEZ6wAnQWRRUZ2CyYa4AN1FeAHsSgq4S2fULts1q4yjlWUDc7tf:mBJYtfZmQWRRQzIRIGh5RDcx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154D2983DAED55573E3BBCAB5C5F640C6BA70B5233A01585E50EB03810D13B96ECA1A1E
sha3_384: 29336ef41d47c91c4636b8285b3a2c4406dbe8bb2d1f0780f6eec2dedbfda85fbd3d66383a102bd676c5f161837121ea
ep_bytes: 81ec3408000053555633f65756897424
timestamp: 2014-05-13 06:44:14

Version Info:

0: [No Data]

Malware.AI.484471131 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Dropper.Upatre-9987660-0
FireEyeGeneric.mg.63e8e9edce369b8d
ALYacTrojan.Ppatre.Gen.1
MalwarebytesMalware.AI.484471131
VIPRETrojan.Ppatre.Gen.1
SangforTrojan.Win32.Save.a
Cybereasonmalicious.dce369
BitDefenderThetaGen:NN.ZexaF.36164.buX@amb1nboi
VirITTrojan.Win32.Upatre.AS
CyrenW32/S-654ac031!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Waski.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.gaapvu
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Upatre.we
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1315817
DrWebTrojan.DownLoad3.33216
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
Trapminesuspicious.low.ml.score
SophosMal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojanSpy.Zbot.ffhh
AviraHEUR/AGEN.1315817
MAXmalware (ai score=80)
Antiy-AVLTrojan[Downloader]/Win32.Waski
XcitiumTrojWare.Win32.TrojanDownloader.Waski.ADW@8mzp93
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.123FQL1
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.R158192
Acronissuspicious
VBA32SScope.Trojan-Downloader.1454
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!8.B5 (TFE:3:JrFJf4jCRlD)
YandexTrojan.GenAsa!zfalv5UzsQI
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.B!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.484471131?

Malware.AI.484471131 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment