Malware

About “Fugrafa.251293 (B)” infection

Malware Removal

The Fugrafa.251293 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.251293 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Fugrafa.251293 (B)?


File Info:

name: F4681C61CB2B94CC3104.mlw
path: /opt/CAPEv2/storage/binaries/9c1e2a78da16080110fbcc0e27bf468f879edb93bac31f799d4fdb1f023711ef
crc32: A1EFB0AE
md5: f4681c61cb2b94cc31048624970993d4
sha1: d821d51b0efffe680f9130c3972b764615fcd7ae
sha256: 9c1e2a78da16080110fbcc0e27bf468f879edb93bac31f799d4fdb1f023711ef
sha512: 7ce185601b0ef23653dc972275688578d8d96196c758e27aee768101512e299b256961872064a5a5d7c25bd47b8ab29cb8b482f697aa3b9d47d6ded6ca36c888
ssdeep: 384:TgEaziQIBt8yguzjEBNQiviL//U8zYpDc7+57ERk95Wk+:T7a/6BlSvW//pzW7hEk+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DA33BF33ECDDF2EF13EDEB548B4D0EA6C21791488A2002D7584A84F1C662979DED615
sha3_384: 65b6298728bfabf949d0bdbd362b29ba52dc6f69d47f14917f7f7e38385e906f744106b243bc48396ca050341ba58f6c
ep_bytes: 837c24120ae8b6ffffff29d101c1e889
timestamp: 2004-05-28 09:53:59

Version Info:

0: [No Data]

Fugrafa.251293 (B) also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.251293
FireEyeGeneric.mg.f4681c61cb2b94cc
CAT-QuickHealTrojan.Upatre.ZZ4
ALYacGen:Variant.Fugrafa.251293
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34606.gmX@aebg6tni
CyrenW32/Upatre.NM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.B
BaiduWin32.Trojan-Downloader.Waski.a
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Dropper.Upatre-9944336-0
KasperskyHEUR:Trojan.Win32.Delf.gen
BitDefenderGen:Variant.Fugrafa.251293
NANO-AntivirusTrojan.Win32.Vundo.fncedi
APEXMalicious
TencentTrojan.Win32.Delf.wd
Ad-AwareGen:Variant.Fugrafa.251293
EmsisoftGen:Variant.Fugrafa.251293 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.B@80t362
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader9.19947
ZillyaDownloader.Upatre.Win32.70481
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionPWSZbot-FMO!F4681C61CB2B
SophosML/PE-A + Troj/Zbot-HMB
IkarusTrojan-Spy.Zbot
GDataGen:Variant.Fugrafa.251293
JiangminTrojanSpy.Zbot.fqcv
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.7D7FCD
MicrosoftTrojanDownloader:Win32/Upatre.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Upatre.R477425
McAfeePWSZbot-FMO!F4681C61CB2B
VBA32TrojanDownloader.Upatre
MalwarebytesSimbot.Backdoor.Stealer.DDS
AvastWin32:Waski-B [Cryp]
RisingDownloader.Upatre!8.B5 (RDMK:cmRtazoFf0TUDsxvT5I)
YandexTrojan.GenAsa!G7HTEQf3zWI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
AVGWin32:Waski-B [Cryp]
Cybereasonmalicious.1cb2b9
PandaTrj/Genetic.gen

How to remove Fugrafa.251293 (B)?

Fugrafa.251293 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment