Malware

Malware.AI.595816388 malicious file

Malware Removal

The Malware.AI.595816388 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.595816388 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task

How to determine Malware.AI.595816388?


File Info:

name: AC7C1EE31B2BD1BB28E9.mlw
path: /opt/CAPEv2/storage/binaries/3911a2ee2ecfcd1bf40b4b36c2f00abf1c8d1ce00515149a06c2c9a81d842f4b
crc32: 0C3A31E0
md5: ac7c1ee31b2bd1bb28e9d91ef89cf101
sha1: 8c749cb1f9381b14c95e0c98d311f4aaf8d0b96b
sha256: 3911a2ee2ecfcd1bf40b4b36c2f00abf1c8d1ce00515149a06c2c9a81d842f4b
sha512: 1bb3799b2e9bffc7fd29fdac3e5f5bcb822b1fdaed3c502d13410796c1203157fd10d26767f96005ff91de5f1de4739d444eb4f73b6f1bf9a450386590134c42
ssdeep: 12288:4hqxSLo5C1Ps4Xh4tnPU8zKbeFVcO4BG86kNpnYEd3pVrCBPzic0L9vvO:4HLmCiIheISa9ZNJ3UQL4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D557D21E69ACA50D272553CD723D9FC4E23AE10C9F7481B52D87EFBB7B68524810B72
sha3_384: 50eafc59f6d097f701a303bddd252c7aeaece456694c4e59a02843c459982fc2c0e990cf5402a7c506fc385c5072dcb3
ep_bytes: e884040000e988feffff3b0d68d64300
timestamp: 2020-06-25 10:38:24

Version Info:

0: [No Data]

Malware.AI.595816388 also known as:

LionicTrojan.Win32.NanoBot.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ac7c1ee31b2bd1bb
SkyhighBehavesLike.Win32.Backdoor.th
MalwarebytesMalware.AI.595816388
AlibabaTrojan:Win32/NanoBot.357fee2d
CrowdStrikewin/malicious_confidence_70% (W)
APEXMalicious
ClamAVWin.Malware.Ursu-9849426-0
GoogleDetected
SophosGeneric ML PUA (PUA)
IkarusBackdoor.Nanobot
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.C4814520
McAfeeArtemis!AC7C1EE31B2B
Cylanceunsafe
RisingTrojan.Generic@AI.96 (RDMK:QzEoyDEXMKVdJCTnKnSVeQ)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73713725.susgen
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.36802.uzZ@ayr8PqhO
DeepInstinctMALICIOUS

How to remove Malware.AI.595816388?

Malware.AI.595816388 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment