Malware

What is “Fragtor.44538”?

Malware Removal

The Fragtor.44538 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.44538 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the DanaBot malware family
  • Anomalous binary characteristics

How to determine Fragtor.44538?


File Info:

name: 2B022786F78E56D26332.mlw
path: /opt/CAPEv2/storage/binaries/2d2c67bda5684ec132be9630fd432b0a8f0bf136c3fcdb40ce1958b0716214d5
crc32: FEEDE559
md5: 2b022786f78e56d263327e5280ffeecf
sha1: 0c92b069462156485211a07d03781efec9db4572
sha256: 2d2c67bda5684ec132be9630fd432b0a8f0bf136c3fcdb40ce1958b0716214d5
sha512: 18b24fdf3f90e62c0fa6745eeaba0de45f1587d5b7a54e1de0a72deccdce69ae8f235f8dc8ddfe2c426a19289327874da0ab26ad49a79748b25448d12d42342e
ssdeep: 49152:Q9hL+mWJfawr059WjkxRW+/zZbqrWr79eZ:k5WEPWjkxRDNbq6oZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13785333075ABD4B0D0EB26718576FE66466B7DE2D6E0C2170A413B2C1FC2E609B91B1F
sha3_384: 32d238912112bc435f94ab3aea8ce18ea269d9696904244aba1b6c34fe954756e17d577fceaa4840e97661dc221d7f3f
ep_bytes: e88f2c0000e989feffffcccccccccccc
timestamp: 2021-04-28 01:12:56

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Fragtor.44538 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.44538
FireEyeGeneric.mg.2b022786f78e56d2
ALYacGen:Variant.Fragtor.44538
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00589d2d1 )
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.946215
BitDefenderThetaGen:NN.ZexaF.34294.Rr1@aiS2DxdI
CyrenW32/StopCrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKW
KasperskyUDS:Backdoor.Win32.Agent.gen
BitDefenderGen:Variant.Fragtor.44538
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Fragtor.44538
SophosML/PE-A + Mal/Agent-AWV
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
EmsisoftTrojan.Crypt (A)
APEXMalicious
GDataGen:Variant.Fragtor.44538
AviraTR/Crypt.Agent.wdiif
MAXmalware (ai score=83)
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MVK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R452832
Acronissuspicious
McAfeeLockbit-FSWW!2B022786F78E
MalwarebytesTrojan.MalPack.GS
IkarusTrojan-Ransom.StopCrypt
RisingTrojan.Generic@ML.86 (RDML:Zzxzjvz+CDNGMJF1FEZ3ig)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lockbit.FSWW!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fragtor.44538?

Fragtor.44538 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment