Malware

About “Fugrafa.256019 (B)” infection

Malware Removal

The Fugrafa.256019 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.256019 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Uses suspicious command line tools or Windows utilities

How to determine Fugrafa.256019 (B)?


File Info:

name: 548A96B6ECE498F787FD.mlw
path: /opt/CAPEv2/storage/binaries/dd2b3b70e0ab55365c2661eb5e59bea0f7dc030a84d2af1e84b16548ddf8029e
crc32: 9AD479A1
md5: 548a96b6ece498f787fd3fea4f27a760
sha1: bb06185a6389ecc0da0b25de0e0f764988f15e2a
sha256: dd2b3b70e0ab55365c2661eb5e59bea0f7dc030a84d2af1e84b16548ddf8029e
sha512: c0de3c1eae5158e26224808461fb15150a6a2c9967d25e61b4541bba5fb56e7a49fa540671e0c8cc924c42ee31df44223ee3d5ed45e67484aa3fe051b4801795
ssdeep: 768:RV5ceBb3H9xjXvKBBW5bAzz+zq2H3FdqXkU7u7rfDd:Rt5DjSBBW+v+zq2TIPKfbd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13CC28DC3FA510832DF5441B030725EB8C3BE78657BA98AB39F11FA5129D1851D6362FE
sha3_384: b2482bba147e5dff081be1131a40c5db02d1a269af6c2eeee3e97c64b42f21e3aa55d634da33100600eccfd992d34c1c
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.256019 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.256019
FireEyeGeneric.mg.548a96b6ece498f7
McAfeeGenericRXNV-VM!548A96B6ECE4
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
CyrenW32/Agent.ENB.gen!Eldorado
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fugrafa.256019
AvastWin32:Malware-gen
TencentTrojan.Win32.Selfdel.xb
Ad-AwareGen:Variant.Fugrafa.256019
EmsisoftGen:Variant.Fugrafa.256019 (B)
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!548A96B6ECE4
SophosTroj/PWS-CMJ
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fugrafa.256019
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
VBA32BScope.Trojan.Occamy
MAXmalware (ai score=88)
MalwarebytesMalware.AI.2397151589
RisingTrojan.PSW!1.DE3E (CLASSIC)
IkarusTrojan.DelFiles
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.6ece49
PandaTrj/Genetic.gen

How to remove Fugrafa.256019 (B)?

Fugrafa.256019 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment