Malware

What is “Malware.AI.603527448”?

Malware Removal

The Malware.AI.603527448 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.603527448 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.603527448?


File Info:

name: 4E88D8118FB88EF5B3AE.mlw
path: /opt/CAPEv2/storage/binaries/597c4fd0f31f87c056d1c7295711bc1666f8103855e60dd0e9132fe160101338
crc32: C50BB20F
md5: 4e88d8118fb88ef5b3ae8342c0777448
sha1: b4be6a35500e3bcb6fc92c5b567b5b0ac0bf03fb
sha256: 597c4fd0f31f87c056d1c7295711bc1666f8103855e60dd0e9132fe160101338
sha512: 933f6bedf8d132eaff1c06ce42d1dd2694c6a3d2fd105ac41799ea831e4dd4f6608b55fccf7bd2252e13331ae7277657dccdd1bd720736f1fa72f3412cf65137
ssdeep: 3072:4tZiRVY8voXm3Il+YeopYHxNpZG3l5omfD1L:iZiRVY8voXm3Il+6pYHzTG34mfJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199C3127525679499D948CD36BD940A06A2E0B71A3B7CC7805360E3AFC8964FCBFB8C49
sha3_384: ba9ec81b0e08347b4333e740082acf80b5713c20ef5ed299922c3f0e2906072a88d59906a58c2dbab010594b731ac8c2
ep_bytes: 60be00f040008dbe0020ffff5783cdff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.603527448 also known as:

LionicTrojan.Win32.Cospet.4!c
MicroWorld-eScanWorm.P2P.AM
ClamAVWin.Worm.Fearso-7358009-0
FireEyeGeneric.mg.4e88d8118fb88ef5
CAT-QuickHealTrojan.IgenericIH.S26830202
McAfeeGenericRXAA-AA!4E88D8118FB8
CylanceUnsafe
VIPREWorm.P2P.AM
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00575a021 )
AlibabaWorm:Win32/Eggnog.100d
K7GWTrojan ( 000a4e6a1 )
Cybereasonmalicious.18fb88
BaiduWin32.Worm.Eggnog.a
CyrenW32/Eggnog.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Worm.Win32.Generic
BitDefenderWorm.P2P.AM
NANO-AntivirusTrojan.Win32.Delphi.iarwcx
AvastWin32:Malware-gen
TencentWorm.Win32.Eggnog.a
Ad-AwareWorm.P2P.AM
SophosML/PE-A + Troj/Agent-AJFK
DrWebWin32.HLLW.Google.24577
ZillyaWorm.Eggnog.Win32.45114
TrendMicroTROJ_GEN.R002C0PKG22
McAfee-GW-EditionBehavesLike.Win32.Gbot.cc
Trapminemalicious.high.ml.score
EmsisoftWorm.P2P.AM (B)
IkarusBackdoor.Win32.Netbus
GDataWin32.Worm.Fearso.A
JiangminTrojan/Cospet.gv
AviraDR/Delphi.Gen
Antiy-AVLWorm/Win32.Eggnog
ArcabitWorm.P2P.AM
ZoneAlarmUDS:Worm.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Worm/Win.Eggnog.R490117
Acronissuspicious
BitDefenderThetaAI:Packer.DD98A70021
ALYacWorm.P2P.AM
MAXmalware (ai score=89)
VBA32BScope.Worm.Pluto
MalwarebytesMalware.AI.603527448
TrendMicro-HouseCallTROJ_GEN.R002C0PKG22
RisingWorm.Win32.Eggnog.b (CLOUD)
YandexWorm.Eggnog!a7tVSEfkP8o
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Eggnog.E!worm
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.603527448?

Malware.AI.603527448 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment