Malware

Fragtor.101807 (B) (file analysis)

Malware Removal

The Fragtor.101807 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.101807 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.101807 (B)?


File Info:

name: 3C7D7EB33439107913BB.mlw
path: /opt/CAPEv2/storage/binaries/41a85826891e6a05b3248fd02644974231c934e9cd7ba619537e165d7a05c1db
crc32: AD100399
md5: 3c7d7eb33439107913bbabbde9c96636
sha1: c6d84714c375093ab1fd77fd7fae4d9f64e4bde6
sha256: 41a85826891e6a05b3248fd02644974231c934e9cd7ba619537e165d7a05c1db
sha512: 932f420d1b7dea5691211e00e815bfae53982293d7ec420b1ce95bc2b74a7c04f2cef84067574f4fa9e0d975b7351b916a950d9d946940f7c00548f835f70b40
ssdeep: 768:lv40by9xjXvKBBW5bcuV+7+Yr6aBlcmC63JU:liDjSBBWP+5rHBlcO3JU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CEC29F87F7D04866DD81093270F3E9B8C6BEB9207ED296435B21EA2A18F1854EF5534F
sha3_384: 03da92908db5a8861ab4f6bba9041d2af181d45acb6008c179129b73354e6c0ab8371e71c97843f36a6c039b99ff9adf
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.101807 (B) also known as:

MicroWorld-eScanGen:Variant.Fragtor.101807
FireEyeGeneric.mg.3c7d7eb334391079
McAfeeGenericRXNV-VM!3C7D7EB33439
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.334391
ArcabitTrojan.Fragtor.D18DAF
CyrenW32/Agent.ENB.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.101807
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.101807
TACHYONTrojan/W32.Fugrafa.26112
SophosTroj/PWS-CMJ
F-SecureHeuristic.HEUR/AGEN.1234650
DrWebTrojan.MulDrop20.10627
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!3C7D7EB33439
EmsisoftGen:Variant.Fragtor.101807 (B)
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MicrosoftTrojanDownloader:Win32/Emotet!ml
ZoneAlarmHEUR:Trojan.Win32.SelfDel.vho
GDataGen:Variant.Fragtor.101807
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
ALYacGen:Variant.Fragtor.101807
MAXmalware (ai score=88)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.5437263.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fragtor.101807 (B)?

Fragtor.101807 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment