Malware

Malware.AI.2878523023 malicious file

Malware Removal

The Malware.AI.2878523023 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2878523023 virus can do?

  • Unconventionial language used in binary resources: Spanish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.2878523023?


File Info:

name: 1E88C93CC9219EE335D3.mlw
path: /opt/CAPEv2/storage/binaries/12610cf31b3bd2a9c6e1a2af77055ad22cd237061ca37391ffb10a9c45831117
crc32: 42B3130B
md5: 1e88c93cc9219ee335d39be336994ac8
sha1: dab6531529f3503e019e9bd39ef855ac9033890a
sha256: 12610cf31b3bd2a9c6e1a2af77055ad22cd237061ca37391ffb10a9c45831117
sha512: 5c4a39132290bb817a059effebc8d5b8f9bcfe7f538736a3fcccf9e1a48fef7ea697101f3b24b8951776bf8eedd21c5e406a6d0712c4a7824156c339c6004bc6
ssdeep: 12288:aYV6MorX7qzuC3QHO9FQgd5sC9cZsnugi0q:JBXu9HGajZSAx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E9423902F91AF5EE0D547FDB57BA541E027CCD692A827C90899F614F97AFC4E4030A3
sha3_384: 57d947de8016c74a91fb90d36feab1fe8063878ccc4efe3029d729de08b2c541d3568fc42bf07f5e791bbb8e18acfbc0
ep_bytes: 60be002048008dbe00f0f7ff57eb0b90
timestamp: 2020-06-18 15:58:57

Version Info:

FileVersion: 1.20.06.170
Comments: This file is part of a set of private tools for IT technicians in Spain. More info at www.pixe.es. E-mail contact: contacto@pixe.es.
FileDescription: PiXE-Server - Servidor de PiXE
ProductVersion: 06.20
LegalCopyright: Pablo Antonio Navarro Reyes © 2011-2019
InternalName: pixe-server.exe
ProductName: PiXE-Server - Servidor de PiXE
CompanyName: PiXE.es
Translation: 0x040a 0x04b0

Malware.AI.2878523023 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.4!c
SkyhighBehavesLike.Win32.TrojanAitInject.gc
McAfeeArtemis!1E88C93CC921
MalwarebytesMalware.AI.2878523023
SangforTrojan.Win32.Agent.Vi1b
AlibabaTrojanDropper:JS/ScriptSH.0d88d2a7
Elasticmalicious (moderate confidence)
AvastWin32:Malware-gen
ClamAVWin.Dropper.NetWire-9805228-0
F-SecureHeuristic.HEUR/AGEN.1321600
DrWebTrojan.DownLoader34.38804
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=99)
GoogleDetected
AviraHEUR/AGEN.1321600
VaristW32/ABTrojan.EESA-3586
Antiy-AVLTrojan[Packed]/Win32.Autoit
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Agent.C2127836
VBA32Trojan-Downloader.Autoit.gen
Cylanceunsafe
RisingTrojan.Obfus/Autoit!1.BEDE (CLOUD)
IkarusTrojan.Worm
MaxSecureTrojan.Malware.208878654.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.2878523023?

Malware.AI.2878523023 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment