Malware

What is “Fragtor.28478”?

Malware Removal

The Fragtor.28478 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.28478 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Fragtor.28478?


File Info:

name: C591544DE8E73B34D012.mlw
path: /opt/CAPEv2/storage/binaries/b463cd1b83e5a78597f6d93e20e73c40efccfb806ecf9fbae0065052945d051b
crc32: A9659184
md5: c591544de8e73b34d012dbe5ec836ca0
sha1: 31ceaf88a9bfc523868f402fde6fe084069ccca0
sha256: b463cd1b83e5a78597f6d93e20e73c40efccfb806ecf9fbae0065052945d051b
sha512: 9fb442c733f812ff14324a27dd5f75d4766f030e01920abe1ffc355dd1d2be2cbb97427e97459a32380a0fd3bf6dbcfa6a205d779853c2724d02cd1c644e40ed
ssdeep: 12288:+HdTyucP4SQfdyed90fbM+/e1MR3UsuHqRFV5ZACHmBKM+68jK9Hs2KVhE:iGucARkBMge1YUsucVDmEVjd1V
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1220533E7157CC312DAEF1A3470ABE04A318C261644EA5E5FBDC3C5536F8076985AD1CB
sha3_384: 7ef7c58d0acb25cc280336b50a506c16fd82204971167aff2d0747ff368e365f70b8cca4c85b697cc592442397755fea
ep_bytes: b80000000053465981c674f7639281ee
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.28478 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.28478
FireEyeGen:Variant.Fragtor.28478
McAfeeGenericRXAA-FA!C591544DE8E7
CylanceUnsafe
ZillyaTrojan.Copak.Win32.135089
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.8a9bfc
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AUY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Coinminerx-9833424-0
KasperskyUDS:Trojan.Win32.Copak
BitDefenderGen:Variant.Fragtor.28478
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosML/PE-A + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJ221
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftGen:Variant.Fragtor.28478 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.haebf
AviraHEUR/AGEN.1140994
Antiy-AVLTrojan/Generic.ASBOL.C689
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataGen:Variant.Fragtor.28478
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4330504
BitDefenderThetaGen:NN.ZexaF.34182.XmW@aKBFT5i
ALYacGen:Variant.Fragtor.28478
MAXmalware (ai score=89)
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
TrendMicro-HouseCallTROJ_GEN.R002C0DJ221
RisingTrojan.Kryptik!1.D12D (CLOUD)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Fragtor.28478?

Fragtor.28478 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment