Malware

What is “Fragtor.43105 (B)”?

Malware Removal

The Fragtor.43105 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.43105 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the OnlyLogger malware family
  • Attempts to modify proxy settings

Related domains:

postbackstat.biz
wpad.local-net
forwardstorage.biz

How to determine Fragtor.43105 (B)?


File Info:

name: 1398943B8E6FB85F702A.mlw
path: /opt/CAPEv2/storage/binaries/c4fff9c2344b9fa3cc4b40b50716ee7bf719c0121bbd6aa278d96d4519450353
crc32: 1540177F
md5: 1398943b8e6fb85f702a2e247158b020
sha1: 84f2dc9fcb0016350b14ef488a48faa466707b5c
sha256: c4fff9c2344b9fa3cc4b40b50716ee7bf719c0121bbd6aa278d96d4519450353
sha512: 0a42b7fcb2811aabdea48b440d334dc693a5467f062bfbc876d18efe15777e0e84db7a46c5fb1201c62763dc10c1cfd3593485390faf80877438a63cd274f0e1
ssdeep: 6144:imPWFxxvKLbdzZQSxbZdr6VXQvbg9Ts0nHjMJh3pCEYS:imuFxx6bT7QXWGjMJdp7X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B054E05133E28533E5A737345934EB620ABBBDB26930C28B6758366D9E723C05E35783
sha3_384: 1fc88fb86786a1e2fbc33471ead2e081aaa607ee26f4c81290ecebe5b25c4b976835a103bf21a5153d1f16e9e3624c1c
ep_bytes: e8683b0000e989feffffcccccccccccc
timestamp: 2021-04-25 23:02:01

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.37.25
Translation: 0x0117 0x046a

Fragtor.43105 (B) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeGenericRXQU-HP!1398943B8E6F
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058aa4d1 )
K7AntiVirusTrojan ( 0058aa4d1 )
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKB
APEXMalicious
KasperskyVHO:Trojan-Downloader.Win32.Agent.gen
BitDefenderTrojan.GenericKDZ.80582
MicroWorld-eScanGen:Variant.Midie.104503
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Midie.104503
EmsisoftGen:Variant.Fragtor.43105 (B)
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dc
FireEyeGeneric.mg.1398943b8e6fb85f
SophosML/PE-A + Troj/Krypt-BO
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.1XTFOTC
ArcabitTrojan.Midie.D19837
MicrosoftRansom:Win32/StopCrypt.PU!MTB
AhnLab-V3Trojan/Win.MalPE.R451835
Acronissuspicious
ALYacGen:Variant.Fragtor.43105
VBA32Malware-Cryptor.2LA.gen
CylanceUnsafe
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazoD+gzs5pmZ3cR7kaMDeZ6E)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HNKE!tr
BitDefenderThetaGen:NN.ZexaF.34294.sq0@aa7li5lO
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.fcb001
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.43105 (B)?

Fragtor.43105 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment