Malware

suspected of Archive.MailBomb removal

Malware Removal

The suspected of Archive.MailBomb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What suspected of Archive.MailBomb virus can do?

  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine suspected of Archive.MailBomb?


File Info:

name: ECBD2A12E175A90E2A8D.mlw
path: /opt/CAPEv2/storage/binaries/21f9e234c80d9181510c77fc3e1b2c3b6a22eff095634136c0312b97cab15315
crc32: E9C321C2
md5: ecbd2a12e175a90e2a8d97a4ca3c715a
sha1: ba4b0be239775326911bbec625bbd77e4d76daf4
sha256: 21f9e234c80d9181510c77fc3e1b2c3b6a22eff095634136c0312b97cab15315
sha512: 3511183f7dfe4983106b87ec17b1a25f4ab509149fd58ab1d076c1e238a976fc3cff220da796156ef17f26f47467ae7a8f2c11f8f7b97c7e4491ff2bfeb58a43
ssdeep: 12288:ZBdlwHRn+WlYV+T1/PlNRNQfuxiksTaS/uYQuWJeiPLQu/HdEhnHFy:ZBkVdlYAB/PZw0EDWYQuieizQyoHFy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10525BF93B1913872E11746360F23EFA4C8ADFE565B7EAEC273BAE6778060D80D5142D4
sha3_384: f53cb4f7b975506c8ec2ef6ccaa7a77309164294e4d6d7616869011863e91ac2cf9b9fc92275028bd10c925181a7567d
ep_bytes: e8c6040000e978feffffcccccccccccc
timestamp: 2023-10-03 07:51:19

Version Info:

0: [No Data]

suspected of Archive.MailBomb also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S5603564
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1827528
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
BaiduMulti.Threats.InArchive
VirITTrojan.Win32.Genus.TMT
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.njRAT-9986242-0
KasperskyUDS:Trojan.Win32.Diztakun
NANO-AntivirusTrojan.Script.KillFiles.dczvem
SophosGeneric ML PUA (PUA)
F-SecureMalware.BAT/Nowinpanel.A
DrWebBAT.controlpanelhide.2
FireEyeGeneric.mg.ecbd2a12e175a90e
SentinelOneStatic AI – Malicious SFX
Antiy-AVLTrojan[ArcBomb]/Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.BAT.Assoc.gen
VaristBAT/Agent.ANS
MAXmalware (ai score=69)
DeepInstinctMALICIOUS
VBA32suspected of Archive.MailBomb
MalwarebytesGeneric.Malware.AI.DDS
IkarusTrojan.BAT.Disabler
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove suspected of Archive.MailBomb?

suspected of Archive.MailBomb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment