Malware

What is “Fugrafa.152749”?

Malware Removal

The Fugrafa.152749 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.152749 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
edgedl.me.gvt1.com

How to determine Fugrafa.152749?


File Info:

crc32: FDB3420E
md5: 0e7ebae4eae2c367c068512abdf6c3dd
name: 0E7EBAE4EAE2C367C068512ABDF6C3DD.mlw
sha1: 6ec282cc3363d1025f8fcb8e9888c8b5cf993faf
sha256: 003d058b82deed9189204f9adbe14163cc4dca8d0508a4480176e8fd05a2ab3f
sha512: 5bed921d184d2298c7bf640eedd643cc01b47067b65c20d51bbc99a6d3c5a575295dfddfe4e8ae79e4d53004ff4e101d78147cb18f0c3ecc856b6b2aaff7c9da
ssdeep: 12288:yNMGdcu4xJP1Lr+PG4O0RpZ0Uud3rSkJwJ4iKDFm:4uJf4RHp83rbI4Rhm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 7567567 5675
InternalName: 56645 764756
FileVersion: 345345 34 534
CompanyName: 525 45 3534 534 5
ProductName: 675 7567 5
ProductVersion: 7567 56 756 75 756
FileDescription: 34534 34534 345
OriginalFilename: 6756 756 756
Translation: 0x0419 0x04b0

Fugrafa.152749 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Fugrafa.152749
SangforTrojan.Win32.Save.a
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Fugrafa.152749
MicroWorld-eScanGen:Variant.Fugrafa.152749
Ad-AwareGen:Variant.Fugrafa.152749
FireEyeGeneric.mg.0e7ebae4eae2c367
EmsisoftGen:Variant.Fugrafa.152749 (B)
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Hynamer.C!ml
ArcabitTrojan.Fugrafa.D254AD
GDataGen:Variant.Fugrafa.152749
MAXmalware (ai score=88)
VBA32BScope.Trojan.Skeeyah
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM20.1.596F.Malware.Gen

How to remove Fugrafa.152749?

Fugrafa.152749 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment