Malware

Fragtor.35041 (B) (file analysis)

Malware Removal

The Fragtor.35041 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.35041 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Attempts to delete or modify volume shadow copies
  • Writes a potential ransom message to disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Exhibits possible ransomware file modification behavior
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.35041 (B)?


File Info:

name: E368927CADA2CCB2A695.mlw
path: /opt/CAPEv2/storage/binaries/8f3099dd9b3da0fdd6c4d3d910bceeb9d21bfa91700667231100143ce27fed0d
crc32: F163B70E
md5: e368927cada2ccb2a695c777e8b81a55
sha1: 73884d91530b7ac07d1468081c90473f13eae103
sha256: 8f3099dd9b3da0fdd6c4d3d910bceeb9d21bfa91700667231100143ce27fed0d
sha512: b86a4e1fca92371798b937a2530b407a047c9ec0078a3740cc9c74406917af71cb471ad0de70a3f0355bcc3560dd743caf4e85e3fbdf6ba3fc685afbf5f260ce
ssdeep: 98304:zuf77YIlKPycR+VCMeSbxo/rAtzwH5qyO4d/RGHNxlokgv3egHLA6t:qD0Ic3EVjyTAtzglxkHNzokEH0U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A4623B71222005AD0D6CC3E5A37BDF571F753AB8F42AC7865AB2AD137214A5B303A53
sha3_384: 6111c3280e989069c9b86cc711d3f98241a35238b113d89af85b579ed29598b9bdd7d4da1d24c7898938076677f325c3
ep_bytes: 684da5dd3fe8a68a0700498b38418a58
timestamp: 2022-05-22 02:39:17

Version Info:

0: [No Data]

Fragtor.35041 (B) also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fragtor.35041
FireEyeGeneric.mg.e368927cada2ccb2
ALYacGen:Variant.Fragtor.35041
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Save.a
Cybereasonmalicious.1530b7
BitDefenderThetaGen:NN.ZexaF.34742.@FW@aag!akpi
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
BitDefenderGen:Variant.Fragtor.35041
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Fragtor.35041
EmsisoftGen:Variant.Fragtor.35041 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fragtor.35041
WebrootW32.Trojan.Gen
MAXmalware (ai score=85)
MicrosoftRansom:Win32/Babuk.SIB!MTB
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E368927CADA2
VBA32BScope.TrojanRansom.Crypmod
APEXMalicious
RisingTrojan.Generic@AI.93 (RDML:nTHS1IFg4ztIBxWOI63L7Q)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Fragtor.35041 (B)?

Fragtor.35041 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment