Malware

What is “Fragtor.31206”?

Malware Removal

The Fragtor.31206 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.31206 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Fragtor.31206?


File Info:

name: E5C17828258108321D24.mlw
path: /opt/CAPEv2/storage/binaries/e2623027fe5fb30da4de633eb6186b0d938ff8768d20377f64e65eea482665a5
crc32: 19674CA7
md5: e5c17828258108321d243437926f6e4d
sha1: f622744fa1f749581b430edb91c675f87bb9cd38
sha256: e2623027fe5fb30da4de633eb6186b0d938ff8768d20377f64e65eea482665a5
sha512: 5cb3af89c596f1dcc661d4109ef3cf15d48075465c0df0353e598c64d81c8ab5ec482d140a64cf0b7f09d087afaa9740918aafe33147dd43ec6a514db6856a54
ssdeep: 49152:3NQkjxfgYZDOEl8EAQK8O2N5BunQR1BfJlu+nm4gcsVXiPUa+nWL9TeMGi2hd6CQ:9QkjxnOdEFtFuQf5n/TunWL9d2L68
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T150E533D6EA668A97DEB743F397438C9E2C3C655623C5E97E74D60A0932C00B70A14CE7
sha3_384: d86492e6220bd36128d15f9574baf36b738b067d45f90ea048433c07cc5a59e8f81cd6cb51dda7c315a51e8edb061469
ep_bytes: 83ec04c70424000000005b5183ec04c7
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Fragtor.31206 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.31206
FireEyeGeneric.mg.e5c1782825810832
ALYacGen:Variant.Fragtor.31206
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00576fb91 )
K7GWTrojan ( 00576fb91 )
Cybereasonmalicious.fa1f74
BitDefenderThetaGen:NN.ZexaF.34294.XmW@a4p9k1g
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
KasperskyUDS:Trojan.Win32.Copak
BitDefenderGen:Variant.Fragtor.31206
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Fragtor.31206
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Fragtor.31206 (B)
APEXMalicious
GDataGen:Variant.Fragtor.32828
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C688
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Gen
McAfeeGenericRXAA-FA!E5C178282581
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt.UPX
IkarusTrojan.Win32.Injector
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Fragtor.31206?

Fragtor.31206 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment