Malware

Fragtor.44768 (file analysis)

Malware Removal

The Fragtor.44768 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.44768 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Uses IOCTL_SCSI_PASS_THROUGH control codes to manipulate drive/MBR which may be indicative of a bootkit
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • Attempted to write directly to a physical drive

Related domains:

isatap.local-net

How to determine Fragtor.44768?


File Info:

name: F8E7115FFEC350D1B0EB.mlw
path: /opt/CAPEv2/storage/binaries/e3e3c3435b619607d3b39baa6c01105629b6fd7f2e457b8ae5a53827634474c7
crc32: 1987A00C
md5: f8e7115ffec350d1b0eb25ac5a1b3b52
sha1: 6cb0549166f73c9e3c4345d7a2ac729afb501fd0
sha256: e3e3c3435b619607d3b39baa6c01105629b6fd7f2e457b8ae5a53827634474c7
sha512: fbfac8590e8d409de1366e86540e634f2591f76d265153ffd4774cf37b7b6affaf2b77d964d26c564b065aaa6b9fe5997c2bca952f3bf2b41b75851274834f34
ssdeep: 12288:YZMf9HKo9kgiNDhg4l8Q4iMYSO1MHa3JR1YRqRJSAo:YKmg6paHclY4Dro
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BB412107670E176D6AB393098A186612A777C732231835B3761933F3F317D0EBA57A6
sha3_384: aa2751e5da3b8c46984714b8bc4af5be5a7591561ad4ec111ac1e218e3b33c1c57b9f316f301ef9fc6dab786df7bd5c0
ep_bytes: e8502a0000e989feffffcccccccccccc
timestamp: 2021-01-30 03:04:08

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0114 0x046a

Fragtor.44768 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f8e7115ffec350d1
McAfeeLockbit-FSWW!F8E7115FFEC3
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00589d2d1 )
K7GWTrojan ( 00589d2d1 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNLS
APEXMalicious
KasperskyUDS:Trojan.Win32.DiskWriter.gen
BitDefenderGen:Variant.Fragtor.44768
MicroWorld-eScanGen:Variant.Fragtor.44768
Ad-AwareGen:Variant.Fragtor.44768
SophosML/PE-A + Troj/Krypt-BO
EmsisoftGen:Variant.Fragtor.44768 (B)
GDataGen:Variant.Fragtor.44768
MicrosoftTrojan:Win32/CryptInject.FB!MTB
Acronissuspicious
VBA32Backdoor.Mokes
ALYacGen:Variant.Fragtor.44768
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack
RisingMalware.Heuristic!ET#86% (RDMK:cmRtazrmgzDQWIvQykzHstN6npuA)
SentinelOneStatic AI – Malicious PE
BitDefenderThetaGen:NN.ZexaF.34294.Fq0@aqvY6udG
MaxSecureTrojan.Malware.300983.susgen

How to remove Fragtor.44768?

Fragtor.44768 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment