Malware

Fragtor.23785 (file analysis)

Malware Removal

The Fragtor.23785 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.23785 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.23785?


File Info:

name: E9CEDD5D93706A559E13.mlw
path: /opt/CAPEv2/storage/binaries/2fec88cd75d2a0f8f130b7b20d456689c2ae3fef260071bb969e3255704aa4f4
crc32: D3B90C41
md5: e9cedd5d93706a559e13b03ed3c7e50d
sha1: af09d957c485d52ac21064a951c51039e13f2dd7
sha256: 2fec88cd75d2a0f8f130b7b20d456689c2ae3fef260071bb969e3255704aa4f4
sha512: 651502366e704ec9683464b1b1560853c9b86328f61009b4815f12321b763c0b26c247246f036e579cb32ec51e7083dc83a2897b7d883fe3cd540671236c5a8d
ssdeep: 49152:qj4Jg7FBQL/NRBoL7LeAVPA2JDQ3TCl6OHrOrpopRGqP:qbxOL/tS7LND8TyhHGmR/P
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15AB5335D39E75CF4DE8984315D934B8C8181D2F0C4C90A2DAD7B0A74A687EECDE168BE
sha3_384: 1c956439970989636bc5998bc37a33efc1635c4ed861f113196f6da8e64f6856d27512fa2faa4b9de6d7a067756633b2
ep_bytes: bb000000005781ea91429bdc8b342483
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.23785 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Fragtor.23785
FireEyeGen:Variant.Fragtor.23785
ALYacGen:Variant.Fragtor.23785
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.7c485d
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aW3z7Tn
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Fragtor.23785
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.23785
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.Fragtor.23785 (B)
APEXMalicious
GDataGen:Variant.Fragtor.23785 (2x)
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C689
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
MicrosoftTrojan:Win32/Injector.RAQ!MTB
SentinelOneStatic AI – Malicious PE
AhnLab-V3Malware/Gen.RL_Reputation.R364784
McAfeeGenericRXAA-FA!E9CEDD5D9370
VBA32Trojan.Packed
MalwarebytesTrojan.Injector
RisingTrojan.Kryptik!1.D12D (RDMK:cmRtazpflJ1CxUNSylQoX6nBhZhC)
YandexTrojan.Kryptik!3EghCQNrKpw
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Fragtor.23785?

Fragtor.23785 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment