Malware

Fragtor.46351 malicious file

Malware Removal

The Fragtor.46351 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fragtor.46351 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Fragtor.46351?


File Info:

name: B39DB07947C2BD7114F6.mlw
path: /opt/CAPEv2/storage/binaries/48f8d5322413ce697216a26ddab6af3420cfd5ae366133837c49727c448d506f
crc32: FE2A5344
md5: b39db07947c2bd7114f6b983580ad4b1
sha1: 36ed28bd53581864c90834ebef933476b60d154a
sha256: 48f8d5322413ce697216a26ddab6af3420cfd5ae366133837c49727c448d506f
sha512: 58fc93d1d87ec5d43789801c10deb75bdcbd63797a5df617000621a29f8607c7fd2f93341010309755520a840e86fa0465da3e98cee901fd7872cf1aa8bfb1d9
ssdeep: 98304:nKoDddhUiTse2UiTsepWUiTsepUiTsepHUse2UiTsepWUiTsePHUse2UiTsepWZP:n7LiwlHFuHFKHFuH5LiluHFKHT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180962322B1D069BFC57668345F7F26EC992D3D12292A5E010FF8CA4D6F39BC0A91B351
sha3_384: 52c8d301d7962fe810e4e27337777748b5bfe2d7841480fcc04061b8a4effaabb048f33e12aeb64011725a0e5d6aa62b
ep_bytes: 558bec83c4f0b818d54600e8d08ef9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Fragtor.46351 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Fragtor.46351
FireEyeGeneric.mg.b39db07947c2bd71
ALYacGen:Variant.Fragtor.46351
MalwarebytesGeneric.Malware.AI.DDS
ZillyaRootkit.Xanfpezes.Win32.12
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZelphiF.36722.@RZ@aq24z8ab
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/HideProc.O potentially unsafe
APEXMalicious
ClamAVWin.Trojan.Hideproc-77
KasperskyTrojan-Downloader.Win32.Banload.aalir
BitDefenderGen:Variant.Fragtor.46351
NANO-AntivirusRiskware.Win32.HideProc.crvalg
AvastWin32:HideProc-N [PUP]
TencentHackTool.Win32.ProcHide.ad
EmsisoftGen:Variant.Fragtor.46351 (B)
F-SecureTrojan.TR/Rootkit.Gen
DrWebTrojan.MulDrop5.15056
VIPREGen:Variant.Fragtor.46351
TrendMicroRTKT_HIDEPROC.BB
McAfee-GW-EditionBehavesLike.Win32.ToolHideProcess.rc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.brtn
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Rootkit.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan[Rootkit]/Win32.Xanfpezes
MicrosoftTrojan:Win32/CoinMiner!pz
ArcabitTrojan.Fragtor.DB50F
ZoneAlarmTrojan-Downloader.Win32.Banload.aalir
GDataGen:Variant.Fragtor.46351
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.R119796
McAfeeGenericRXAA-FA!B39DB07947C2
VBA32TrojanDownloader.Banload
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRTKT_HIDEPROC.BB
RisingTrojan.Generic@AI.84 (RDML:KU2zbnVLg32y7BkPr6JLjw)
YandexTrojan.GenAsa!D+mto3nL4uM
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.500016.susgen
FortinetRiskware/HideProc
AVGWin32:HideProc-N [PUP]
Cybereasonmalicious.d53581
DeepInstinctMALICIOUS

How to remove Fragtor.46351?

Fragtor.46351 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment