Malware

Fragtor.102874 (file analysis)

Malware Removal

The Fragtor.102874 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.102874 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.102874?


File Info:

name: B0C03253BCC50A91B61C.mlw
path: /opt/CAPEv2/storage/binaries/d6c287d3cbdd85aa7014f1311b7bf9602f8f6fe1247cb7b9fc9885a364408498
crc32: C2D5118E
md5: b0c03253bcc50a91b61cb37979678168
sha1: e35f7931aac225a5152f3acd92d7fdcc240d24fd
sha256: d6c287d3cbdd85aa7014f1311b7bf9602f8f6fe1247cb7b9fc9885a364408498
sha512: 08bb246fdf3d32d6b4219c7c78f45651d687b4127436b782af0bb8301a64879c47d94a3f87166b75bff787b5c26905e458c598de534c5d2cc455e27076a13203
ssdeep: 768:8GZnEbgI9xjXvKBBW5bi4JVqx4CNZACM:85DjSBBW1JVqxJ8
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T173C27B47FB904CB0CE9005B935BB897582FF7432273FA5876B65EA32A9E3464D50838D
sha3_384: 2d181e338033cdea330657ed95c87896ef3fcb263145b0da877f63e4af58a424d38b31aae220fca715a60f5a19ca7c3e
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fragtor.102874 also known as:

MicroWorld-eScanGen:Variant.Fragtor.102874
FireEyeGeneric.mg.b0c03253bcc50a91
McAfeeGenericRXNV-VM!B0C03253BCC5
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
Cybereasonmalicious.3bcc50
CyrenW32/Agent.ENB.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/PSW.Agent.OOO
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fragtor.102874
NANO-AntivirusTrojan.Win32.SelfDel.jpepdv
APEXMalicious
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fragtor.102874
SophosTroj/PWS-CMJ
DrWebTrojan.MulDrop20.10627
McAfee-GW-EditionGenericRXNV-VM!B0C03253BCC5
EmsisoftGen:Variant.Fragtor.102874 (B)
IkarusTrojan.DelFiles
GDataGen:Variant.Fragtor.102874
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
VBA32BScope.Trojan.Occamy
ALYacGen:Variant.Fragtor.102874
TACHYONTrojan/W32.Fugrafa.26112
MalwarebytesMalware.AI.2397151589
AvastWin32:Malware-gen
RisingTrojan.PSW!1.DE3E (CLASSIC)
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fragtor.102874?

Fragtor.102874 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment