Malware

Fragtor.107521 (file analysis)

Malware Removal

The Fragtor.107521 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.107521 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

How to determine Fragtor.107521?


File Info:

name: 32B1916ABFF8BF0E7C51.mlw
path: /opt/CAPEv2/storage/binaries/a9f0df941172cc4a9c8b242fd41094033e15fa9c5e3781656df3888a4d47f834
crc32: 296FDFE6
md5: 32b1916abff8bf0e7c51a2584c472451
sha1: 513d99d714985ab53d75894357e4e87c69374862
sha256: a9f0df941172cc4a9c8b242fd41094033e15fa9c5e3781656df3888a4d47f834
sha512: 125f71eec8d4cf6e0fa43593858295507a6b6bffad8b088ab65dcfeb4a06cbfb428da1fb4fdff170f4600f5a504f2d67e288242c2453e45fa70cc989f89990b8
ssdeep: 768:AF7C7RYU67uA+rcceVbJAjO1SntSii0/:+C7mU67J+ri8O1Snp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6D26EC4F2E960FBC47125301B1E033E4869BDF8A9806AC6EB457E531477F92B19638E
sha3_384: 3611adcffb9928e01bc609f1c875306575fe841948e5f7647f24e2b3e30ce50f838e6b178a54fd7748822f892c008aa9
ep_bytes: e96a360000f9830d54804000ffe9a533
timestamp: 2017-07-18 18:03:02

Version Info:

0: [No Data]

Fragtor.107521 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanGen:Variant.Fragtor.107521
FireEyeGeneric.mg.32b1916abff8bf0e
McAfeeArtemis!32B1916ABFF8
CylanceUnsafe
ZillyaTrojan.Agent.Win32.977648
SangforTrojan.Win32.Agent.AALT
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/BScope.fc9a3352
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.abff8b
BitDefenderThetaGen:NN.ZexaF.34786.buW@ayjCX@ci
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.AALT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Agent-7784092-0
KasperskyTrojan.Win32.Agent.qwguxl
BitDefenderGen:Variant.Fragtor.107521
NANO-AntivirusTrojan.Win32.Crypted.ficlat
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Ljtx
Ad-AwareGen:Variant.Fragtor.107521
TACHYONTrojan/W32.Agent.29184.ADD
EmsisoftGen:Variant.Fragtor.107521 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
VIPREGen:Variant.Fragtor.107521
TrendMicroTROJ_FRS.0NA103E720
McAfee-GW-EditionBehavesLike.Win32.Mytob.mc
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/Agent-BENT
SentinelOneStatic AI – Malicious PE
GDataWin32.Backdoor.Aria.A
JiangminTrojan.Agent.ctti
WebrootW32.Trojan.GenKD
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2D
KingsoftWin32.Hack.Undef.(kcloud)
ArcabitTrojan.Fragtor.D1A401
ViRobotTrojan.Win32.S.Agent.29184.BAH
ZoneAlarmTrojan.Win32.Agent.qwguxl
MicrosoftTrojan:Win32/Occamy.CA9
CynetMalicious (score: 100)
VBA32BScope.Trojan.Agentb
ALYacBackdoor.Agent.Rpsdoor
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallTROJ_FRS.0NA103E720
RisingTrojan.Generic@AI.85 (RDML:TjVR7EFS146PWfZ7Bgy+kg)
YandexTrojan.Agent!hffpKMD+8Zg
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.QWGUXL!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Fragtor.107521?

Fragtor.107521 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment