Malware

Fugrafa.205756 malicious file

Malware Removal

The Fugrafa.205756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.205756 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family

How to determine Fugrafa.205756?


File Info:

name: 3273D34D58D7D91C8364.mlw
path: /opt/CAPEv2/storage/binaries/a6d81c1be498fafe11cb7a94ba3f35e0c51b37d764f000d05e30a4b165071e68
crc32: 98818F36
md5: 3273d34d58d7d91c8364b1bb6ec58a07
sha1: e648c51d1188d0fe0d596dc6dff5bc25432f195e
sha256: a6d81c1be498fafe11cb7a94ba3f35e0c51b37d764f000d05e30a4b165071e68
sha512: 120a562ee43fd7c1d8034171cf09be86c4008704fa9cc1d4079734971162fb48853ba4cd9c4423fcace4cd6cb1b1a8ffe4b4b74366626af2a5cd7302e80d6077
ssdeep: 49152:C+7mIQVHAlIKL7ulCPBULYjraaOOP10iBrEPftiIc:RqISHWlTOoa9Y4tbc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C95336C2741D0B0D17581F229D82C5DA13C91EAB2B5FA2DC0963FC4DADA8725F486FE
sha3_384: a7050a172229cf113c7e0f2d71ba17e0f5b55d2441d9477a710d487373330abd28fcf6dc7a30fe2050eaecbbcf963a2b
ep_bytes: e8bfccffff66f7c20f0709c9e9519019
timestamp: 2018-02-02 13:45:23

Version Info:

0: [No Data]

Fugrafa.205756 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.205756
FireEyeGeneric.mg.3273d34d58d7d91c
ALYacGen:Variant.Fugrafa.205756
CylanceUnsafe
AlibabaPacked:Win32/VMProtect.a9043724
Cybereasonmalicious.d58d7d
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AV
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Fugrafa.205756
NANO-AntivirusTrojan.Win32.RP.eyhihx
AvastWin32:Malware-gen
TencentWin32.Trojan.Gen.Ligp
Ad-AwareGen:Variant.Fugrafa.205756
EmsisoftGen:Variant.Fugrafa.205756 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Fugrafa.205756
MicrosoftTrojan:Win32/Occamy.CA6
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXDR-TR!3273D34D58D7
MAXmalware (ai score=83)
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Generic@AI.96 (RDML:S8vmV9kR2mAmIyh4Thxu4w)
IkarusTrojan.Win32.VMProtect
FortinetW32/GenericRXDR.TR!tr
BitDefenderThetaAI:Packer.4830F1201F
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fugrafa.205756?

Fugrafa.205756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment