Malware

What is “Fragtor.3802”?

Malware Removal

The Fragtor.3802 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.3802 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (43 unique times)
  • Starts servers listening on 0.0.0.0:3105
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • A possible cryptomining command was executed
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
microsoft-com.mail.protection.outlook.com
defeatwax.ru
accounts.snapchat.com
www.google.co.uk
work.a-poster.info
158.102.105.176.dnsbl.sorbs.net
158.102.105.176.bl.spamcop.net
158.102.105.176.zen.spamhaus.org
158.102.105.176.sbl-xbl.spamhaus.org
158.102.105.176.cbl.abuseat.org
auth.api.np.ac.playstation.net
mx3.hotmail.com
mx4.hotmail.com
mx2.hotmail.com
mx1.hotmail.com
mx0a-001b2d01.pphosted.com
mx3.mail.yahoo.co.jp
mx1.hc3464-92.iphmx.com
daiyudenki.co.jp
ip.pr-cy.hacklix.com
www.google.se
r-smtp6.korea.com
mx0a-00191d01.pphosted.com
publicms1.mail2world.com
mail.abrampe.com.br
mx0.gmx.com
mx156.hostedmxserver.com
www.google.ru
al-ip4-mx-vip2.prodigy.net
mail.host-my-mail.com
yabs.yandex.by
mx1.spray.mail2world.com
mx2.nifty.com
www.instagram.com
mx4.beavis99.com
hotmail-com.olc.protection.outlook.com
fastpool.xyz

How to determine Fragtor.3802?


File Info:

crc32: 6DCA03D3
md5: 26a5a30af2a8f19775fb79d1679052e6
name: 26A5A30AF2A8F19775FB79D1679052E6.mlw
sha1: e1cdeb1061c6770b619412e5f06dd73121354e74
sha256: 6a6c76468f25ca6d92463cc715fe615b2b449468a85e9c183693d8ea5a70fff1
sha512: 479196b7479b87f302a16c6e99dfaa1291be9f57f2420c1d68fcc2236d86003b3105a70b1d0b3f92d141c5c5e368a05b40a57e98f19d3cf798b852860003370a
ssdeep: 3072:RHYT/V2WmOfWSnTEXvoH8Gz5sFhQ/XScsYh6gSVywo3c+:RHa5mO//H8XjiC7knGyHM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: fogsmoageke.emi
ProductVersion: 9.51.22.12
Copyright: Copyrighz (C) 2020, fodkageta
Translation: 0x0162 0x0102

Fragtor.3802 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0058098a1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacBackdoor.Tofsee
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058098a1 )
CyrenW32/Kryptik.EUY.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HMAY
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyUDS:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Fragtor.3802
MicroWorld-eScanGen:Variant.Fragtor.3802
Ad-AwareGen:Variant.Fragtor.3802
SophosML/PE-A + Troj/Krypt-W
BitDefenderThetaGen:NN.ZexaF.34058.oq0@aeNDj7li
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.26a5a30af2a8f197
EmsisoftGen:Variant.Fragtor.3802 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GridinsoftRansom.Win32.STOP.ko!se45665
GDataGen:Variant.Fragtor.3802
AhnLab-V3Infostealer/Win.SmokeLoader.R436548
Acronissuspicious
McAfeeTrojan-FTUB!26A5A30AF2A8
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D82C (CLASSIC)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMAY!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwoCNM8A

How to remove Fragtor.3802?

Fragtor.3802 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment