Malware

About “Application.Graftor.714553” infection

Malware Removal

The Application.Graftor.714553 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Graftor.714553 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.x5cai.cn

How to determine Application.Graftor.714553?


File Info:

crc32: C66B286D
md5: 2fad7eb6af061b04a6400aa5974e782a
name: _____________________________________.exe
sha1: f040f6d6978b1f7e2172a02bdd6b100b70aa205c
sha256: 834b0621e2d9fae59423b130aff8944ccc6efa94b99c6ee26ee169a5fa945aa7
sha512: 0e72da2939de5542bdb0e07d97ae7f927d85649e19c45e6779c21c65c3341538d89d0685523b912a9c14173f1d5a4c7080643df5e4c7dadcc26d19ee77831e75
ssdeep: 12288:8sIEPtZzXIDNU7Ntfu4KFin+TLNaR5gyOEtO1R5vySoSw/TTmr:cDpFx3NaR5gyk13KBbTmr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Application.Graftor.714553 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Application.Graftor.714553
FireEyeGeneric.mg.2fad7eb6af061b04
CylanceUnsafe
BitDefenderGen:Variant.Application.Graftor.714553
Cybereasonmalicious.6af061
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34132.KmGfaq8d6Qhb
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
ClamAVWin.Malware.Zusy-6840460-0
Ad-AwareGen:Variant.Application.Graftor.714553
SentinelOneDFI – Malicious PE
EmsisoftGen:Variant.Application.Graftor.714553 (B)
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQWare.A!tr
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Application.Graftor.DAE739
TotalDefenseWin32/Oflwr.A!crypt
MAXmalware (ai score=73)
VBA32BScope.Trojan.Downloader
RisingMalware.Heuristic!ET#75% (RDMK:cmRtazqQYWkikMuMHmf9UEow5jMH)
eGambitUnsafe.AI_Score_100%
GDataGen:Variant.Application.Graftor.714553
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Application.Graftor.714553?

Application.Graftor.714553 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment