Malware

Fragtor.26138 (file analysis)

Malware Removal

The Fragtor.26138 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.26138 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.26138?


File Info:

name: FF3E880F6D47FAF2CFC5.mlw
path: /opt/CAPEv2/storage/binaries/9444162bacd1aa42b79c36fadbebc0e16516537ee1f06eedf5d005b47549f7cd
crc32: BF89D5BE
md5: ff3e880f6d47faf2cfc5407e25603eb0
sha1: 8bb10f744e06ca677e966046ac033600e4be1fe9
sha256: 9444162bacd1aa42b79c36fadbebc0e16516537ee1f06eedf5d005b47549f7cd
sha512: 6a2d1f1cc589b8197df1c56fff6278ab9e97acdd921ab87abc170f8845549683f9e9acdb11ad9f93a8dee7eb1e8a40de8fa3cd6616dfb5651d279558ae2feb0d
ssdeep: 98304:aKVM3rwkTl3X5D9yOMGC00iUAW66gdh5yXoDWVGTUb:vI9TMOrC0LvZ6g5hDW8Ub
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T138E533B543D9F472E6E8363F82DF58C63D6142B1C1C2DACCBE5B892735A72218199E31
sha3_384: ff07db4ae857a861b5d74379503b7914b3690da5ce9d51a7b7780911fc8c7d3589095609542761f5c4011cc4b299296b
ep_bytes: 68000000005b5621c901c98b3c2483c4
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.26138 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.26138
FireEyeGen:Variant.Fragtor.26138
ALYacGen:Variant.Fragtor.26138
CylanceUnsafe
ZillyaTrojan.Copak.Win32.160669
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
BitDefenderThetaGen:NN.ZexaF.34062.epZ@aSK7X2m
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Fragtor.26138
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.26138
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Fragtor.26138 (B)
APEXMalicious
GDataGen:Variant.Fragtor.26138 (2x)
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C68D
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366210
McAfeeGenericRXAA-FA!FF3E880F6D47
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Kryptik!vdG5IcUCNos
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.44e06c
PandaTrj/Genetic.gen

How to remove Fragtor.26138?

Fragtor.26138 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment