Malware

Malware.AI.2888275169 (file analysis)

Malware Removal

The Malware.AI.2888275169 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2888275169 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Malware.AI.2888275169?


File Info:

name: 017E76298376668C6E07.mlw
path: /opt/CAPEv2/storage/binaries/7ca9af43e051db0af6522848a1053871ea6b88cd97376bdf4297429b61f7e113
crc32: 683EE894
md5: 017e76298376668c6e072d7d68aa9eb9
sha1: 1e8940024c6d8fc65aa82b9a520e0e56c02fb209
sha256: 7ca9af43e051db0af6522848a1053871ea6b88cd97376bdf4297429b61f7e113
sha512: a624d67cb4b77b62ef87305292416693d993c2cbf87ae4849e4fa1f1956273cdacfd8cba3748cacecac780d7edad362ef81d95e09a0d51f49ba5151c677dcfb2
ssdeep: 98304:luWGLKGcFiLPs+uSKVcwNVX+RdnMD8fvrMY01k80fKcU7s5KkQycSCubgaNpNgHE:6qUHKVcwToCoXrMyT4s5DbZLKfVC
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1182622BB1CC05091EC912E30DE15ACA518475D2E6AEC6D2F1F86F1E836F6AE1F49C613
sha3_384: 1f75457688cf810ad80e012679df6e2eb58b1f8825cb194421f6e3df041238d356d0ce7078e49932d90dd14395512aab
ep_bytes: 53565755488d3555e1b8ff488dbe0020
timestamp: 2021-01-22 13:27:36

Version Info:

0: [No Data]

Malware.AI.2888275169 also known as:

LionicRiskware.Win64.Miner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Miner.43
FireEyeGeneric.mg.017e76298376668c
McAfeeArtemis!017E76298376
K7AntiVirusAdware ( 0057f2531 )
BitDefenderGen:Variant.Application.Miner.43
K7GWAdware ( 0057f2531 )
Cybereasonmalicious.983766
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.SQ potentially unwanted
Kasperskynot-a-virus:HEUR:RiskTool.Win64.Miner.gen
AlibabaRiskWare:Win64/Miners.20436458
Ad-AwareGen:Variant.Application.Miner.43
EmsisoftGen:Variant.Application.Miner.43 (B)
DrWebTool.BtcMine.2508
McAfee-GW-EditionBehavesLike.Win64.PUP.rc
SophosGeneric PUA BO (PUA)
IkarusPUA.CoinMiner
MAXmalware (ai score=76)
GridinsoftRansom.Win64.Gen.sa
MicrosoftPUA:Win32/Puamson.A!ml
GDataGen:Variant.Application.Miner.43
CynetMalicious (score: 100)
ALYacGen:Variant.Application.Miner.43
MalwarebytesMalware.AI.2888275169
SentinelOneStatic AI – Malicious PE
FortinetAdware/Miner
AVGWin64:HacktoolX-gen [Trj]
AvastWin64:HacktoolX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.2888275169?

Malware.AI.2888275169 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment