Malware

About “Fugrafa.257035” infection

Malware Removal

The Fugrafa.257035 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.257035 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality

How to determine Fugrafa.257035?


File Info:

name: E45FB0DAB7FEC4D9BDA3.mlw
path: /opt/CAPEv2/storage/binaries/409c3a9b86dbb442fa94a54215e59128130d1c719516719ee46787bc38e406a3
crc32: 7D8BC085
md5: e45fb0dab7fec4d9bda3b713d68ae03f
sha1: 2f9cfd1b7769f39e2bb6560c4743ef44e9910c8c
sha256: 409c3a9b86dbb442fa94a54215e59128130d1c719516719ee46787bc38e406a3
sha512: 8dae50bb7239fd276f03eae93bbdd9d740971219f2199595cc105104450983ea2b57e3be3f9b63558890b04c65131741d58ed600d1f33f6504dec0f762e32ead
ssdeep: 768:s4XZboa8C9xjXvKBBW5bLTLTf1MtaSFM:s8LDjSBBWVTv1E9FM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T177C2AF93F6E089B5EFA00471127119F683FF7C30FB1AE9625F21E91C09B5856DA0D28A
sha3_384: 53a096958936ad62e18f2a5a63329a416544a1b0d8c0259aa09ec1e976c6806b4d99023821a10097eb2823070253be1f
ep_bytes: e8b1020000e974feffff558becff7508
timestamp: 2020-12-13 23:46:04

Version Info:

0: [No Data]

Fugrafa.257035 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.257035
FireEyeGeneric.mg.e45fb0dab7fec4d9
McAfeeGenericRXNV-VM!E45FB0DAB7FE
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 005937271 )
K7GWPassword-Stealer ( 005937271 )
CyrenW32/Agent.ENB.gen!Eldorado
ESET-NOD32a variant of Win32/PSW.Agent.OOO
APEXMalicious
ClamAVWin.Malware.Fugrafa-9950512-0
KasperskyHEUR:Trojan.Win32.SelfDel.vho
BitDefenderGen:Variant.Fugrafa.257035
AvastWin32:Malware-gen
RisingTrojan.PSW!1.DE3E (CLASSIC)
Ad-AwareGen:Variant.Fugrafa.257035
SophosML/PE-A + Troj/PWS-CMJ
ZillyaTrojan.SelfDel.Win32.65008
McAfee-GW-EditionGenericRXNV-VM!E45FB0DAB7FE
EmsisoftGen:Variant.Fugrafa.257035 (B)
JiangminTrojan.Selfdel.rft
AviraHEUR/AGEN.1234650
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Fugrafa.257035
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Reputation.R496203
Acronissuspicious
ALYacGen:Variant.Fugrafa.257035
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.2397151589
TencentTrojan.Win32.Selfdel.xb
IkarusTrojan.DelFiles
MaxSecureTrojan.Malware.5437263.susgen
FortinetW32/SelfDef.26C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ab7fec
PandaTrj/Genetic.gen

How to remove Fugrafa.257035?

Fugrafa.257035 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment