Malware

What is “Fugrafa.28845”?

Malware Removal

The Fugrafa.28845 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.28845 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Fugrafa.28845?


File Info:

name: 03AF5E2794A8F76EFEBE.mlw
path: /opt/CAPEv2/storage/binaries/5d5bdbeebfe7a5f9c4f54f0ad4230c8d2b1a1a01dfc766e58c3e7d04d3ec8839
crc32: 777D272F
md5: 03af5e2794a8f76efebe7e6488a30ab2
sha1: 21d1cd08075ea9ae009805241923d41636d0ddb5
sha256: 5d5bdbeebfe7a5f9c4f54f0ad4230c8d2b1a1a01dfc766e58c3e7d04d3ec8839
sha512: 3cd83ea4402c78118da4b3534c056c1e622afe2d7b0d2927021ddb5439c29ec86eee2e2e71b2aa987d0c78b1f45603be2e7de4e9a2d19f2c58863dbd8286d08e
ssdeep: 3072:BeJA3yUFB9/73DWSagR+IkiquVw/CaQtqD+P5o5z24:8JAZLD3KSaaFoCODky/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B144C30A6A1C034F0F705B68AFA8BB8BD397D701B7884CB53C4179A1664AE9DD31B57
sha3_384: 3352b844ddb8d77a42d778672933968a53c39d0fd0519e4a24177562e4b023a63ecc9f937c68c43af02176cb30ee8a0e
ep_bytes: 558bece818610000e8a3fdffff5dc3cc
timestamp: 2014-09-25 14:21:07

Version Info:

0: [No Data]

Fugrafa.28845 also known as:

LionicTrojan.Win32.Bugor.trZ9
DrWebTrojan.DownLoad3.37956
MicroWorld-eScanGen:Variant.Fugrafa.28845
FireEyeGeneric.mg.03af5e2794a8f76e
McAfeeGenericRXHP-WH!03AF5E2794A8
CylanceUnsafe
ZillyaDownloader.Agent.Win32.260069
SangforTrojan.Win32.Bugor.ai
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/Bugor.827e582e
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.794a8f
BitDefenderThetaGen:NN.ZexaF.34754.muW@aOn@bhpi
VirITTrojan.Win32.Generic.BRFU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RCV
APEXMalicious
KasperskyTrojan.Win32.Bugor.ai
BitDefenderGen:Variant.Fugrafa.28845
NANO-AntivirusTrojan.Win32.DownLoad3.dtrgfr
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10c7f8b8
Ad-AwareGen:Variant.Fugrafa.28845
EmsisoftGen:Variant.Fugrafa.28845 (B)
ComodoMalware@#2sgfqbj0sepph
F-SecureTrojan.TR/Agent.198656.90
VIPREGen:Variant.Fugrafa.28845
McAfee-GW-EditionGenericRXHP-WH!03AF5E2794A8
Trapminemalicious.high.ml.score
SophosMal/Generic-S
GDataGen:Variant.Fugrafa.28845
JiangminTrojan/Bugor.a
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Agent.198656.90
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Agent
KingsoftWin32.Troj.Bugor.ai.(kcloud)
ArcabitTrojan.Fugrafa.D70AD
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan.Win32.Bugor.ai
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
VBA32TrojanDownloader.Agent
ALYacGen:Variant.Fugrafa.28845
TACHYONTrojan/W32.Bugor.198656
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Hitbrovi!8.2DCC (TFE:5:UyJaOU5ResO)
YandexTrojan.DL.Agent!Bm9JaSg+bsg
IkarusTrojan-Dropper.Win32.Agent
FortinetW32/Generic.AC.1F4230!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Fugrafa.28845?

Fugrafa.28845 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment