Malware

Fragtor.44186 malicious file

Malware Removal

The Fragtor.44186 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.44186 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Latvian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Fragtor.44186?


File Info:

name: 3A68CACB5011973D4721.mlw
path: /opt/CAPEv2/storage/binaries/e891322e5d046f40638d60d064393aaaab2217db1da87cae6f08f9befa5db645
crc32: B7A7F963
md5: 3a68cacb5011973d47217ef86f5bc4e1
sha1: 99545a1f41466693ba0b0aebf931f3a08a0845d4
sha256: e891322e5d046f40638d60d064393aaaab2217db1da87cae6f08f9befa5db645
sha512: 6071466050b8cce1695b277df04aff96a7d687833c2c1dd943af74557da038e48bd8fe96446f2ebf163de5eb2aba205e6153281162cdf8f1d884f29103b222ca
ssdeep: 24576:hWwUGYJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ5:h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149B65BD16EEB42CDFAE75A300871AE9456F7BDA6A930415F24C0E12F1D71B8089E3763
sha3_384: 6913a35261ba5cef85772a3265dac67a581679202872420040ea6061487279cbed87b81e154b71fec9202a85fa93c21e
ep_bytes: e8d02a0000e989feffff8bff558bec68
timestamp: 2020-12-27 11:46:19

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Fragtor.44186 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.44186
FireEyeGeneric.mg.3a68cacb5011973d
ALYacGen:Variant.Fragtor.44186
MalwarebytesTrojan.MalPack.GS
K7AntiVirusTrojan ( 00589d2d1 )
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.f41466
BitDefenderThetaGen:NN.ZexaF.34062.@t0@a0PNXtbI
CyrenW32/StopCrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKH
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Fragtor.44186
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Fragtor.44186
EmsisoftTrojan.Crypt (A)
DrWebTrojan.Siggen15.50174
ZillyaTrojan.Kryptik.Win32.3630624
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.VirRansom.vh
SophosML/PE-A + Mal/Agent-AWV
IkarusTrojan-Ransom.StopCrypt
GDataGen:Variant.Fragtor.44186
JiangminBackdoor.Tofsee.ffv
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan[Backdoor]/Win32.Tofsee
MicrosoftTrojan:Win32/Azorult.RT!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R452303
Acronissuspicious
McAfeeLockbit-FSWW!3A68CACB5011
MAXmalware (ai score=88)
VBA32Backdoor.Tofsee
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Kryptik!1.DAC3 (CLASSIC)
YandexTrojan.Kryptik!XmLe2NJ0qks
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_57%
FortinetW32/Kryptik.PSE!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Fragtor.44186?

Fragtor.44186 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment