Malware

Should I remove “Fugrafa.251293”?

Malware Removal

The Fugrafa.251293 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.251293 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Fugrafa.251293?


File Info:

name: 8A7614594B379F45F6F4.mlw
path: /opt/CAPEv2/storage/binaries/7db29966a901d2fa7ffb66f87363c2375424cae7c128174a5e1bec12300360d4
crc32: 363AED70
md5: 8a7614594b379f45f6f4b91a3e1b5976
sha1: 81b79be3e22a0f56e0baf52497c613594d30662e
sha256: 7db29966a901d2fa7ffb66f87363c2375424cae7c128174a5e1bec12300360d4
sha512: 72349300badb036cf26dc58357be4702422747cc3e01005c4f5ea7cf7404ea84e1f3ba70b85c0cf938ea379587bef1533d21d3be7bf8e29d97f25407fb705d50
ssdeep: 384:TgEaziQIBt8yguzjEBNQiviL//U8zYpDc7+57ERk9oTux:T7a/6BlSvW//pzW7hoT+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121A34BF33ACDDF2FF12E9E7588B4D0EB5C21791488A2002E75C4A84F1C662A75DED611
sha3_384: 4f503f05366e6a503c03f8eafaa2096f15baf2e290ead4610c7b5715215c8612005b379b6ea99219b1bb0c529e2d2474
ep_bytes: 837c24120ae8b6ffffff29d101c1e889
timestamp: 2004-05-28 09:53:59

Version Info:

0: [No Data]

Fugrafa.251293 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.251293
FireEyeGeneric.mg.8a7614594b379f45
CAT-QuickHealTrojan.Upatre.ZZ4
ALYacGen:Variant.Fugrafa.251293
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.94b379
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Upatre.NM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
ClamAVWin.Dropper.Upatre-9944336-0
KasperskyHEUR:Trojan.Win32.Delf.gen
BitDefenderGen:Variant.Fugrafa.251293
NANO-AntivirusTrojan.Win32.Vundo.fncedi
AvastWin32:Waski-B [Cryp]
TencentTrojan.Win32.Delf.wd
Ad-AwareGen:Variant.Fugrafa.251293
EmsisoftGen:Variant.Fugrafa.251293 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.B@80t362
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader9.19947
ZillyaDownloader.Upatre.Win32.70481
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionPWSZbot-FMO!8A7614594B37
SophosML/PE-A + Troj/Zbot-HMB
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fqcv
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7D7FCD
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
MicrosoftTrojanDownloader:Win32/Upatre.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Upatre.R477425
BitDefenderThetaGen:NN.ZexaF.34606.gmX@aebg6tni
MAXmalware (ai score=85)
VBA32TrojanDownloader.Upatre
MalwarebytesSimbot.Backdoor.Stealer.DDS
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Upatre!8.B5 (RDMK:cmRtazoFf0TUDsxvT5I)
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
AVGWin32:Waski-B [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Fugrafa.251293?

Fugrafa.251293 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment