Malware

Fugrafa.311994 (B) information

Malware Removal

The Fugrafa.311994 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.311994 (B) virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Fugrafa.311994 (B)?


File Info:

name: 1CD98179B76BD9074FC6.mlw
path: /opt/CAPEv2/storage/binaries/4e92099cf3b2935fd273d111a9f639685c2b8351e867ff619f0638296b863b29
crc32: 2ECAB2F8
md5: 1cd98179b76bd9074fc64a8e31d2df9a
sha1: 3b57d7216fd361752467dee6f870d94f5fa88390
sha256: 4e92099cf3b2935fd273d111a9f639685c2b8351e867ff619f0638296b863b29
sha512: b22cbc5933c53ae41312f3d7f92d0c0364189f3861a1cb8c5c724dd0179b418e4387f97b16ec2d273e9777844c4f00860e12b0327cc0ba5ac23c61e7a702ce92
ssdeep: 768:hXEpuJ84O8eRH++tlFh0pDpuJ84WEi+U6sh7iQroCHOtSr:P8b9l++l8xFt6sh7iQroCuwr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CC36DE6FAD40564D26311B49CF7EA126513BEA429B98A0C30D93B074DB37C264B6B1F
sha3_384: 75a6d178140a082edab7a282c5f6c52c78cf466f677e2be9478c1f61042b5afa4e07dad2d45309bbc08e802115a4b72b
ep_bytes: e88c020000e957fdffff8bff558bec8b
timestamp: 2013-11-21 06:23:38

Version Info:

0: [No Data]

Fugrafa.311994 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoader10.51280
MicroWorld-eScanGen:Variant.Fugrafa.311994
FireEyeGeneric.mg.1cd98179b76bd907
SkyhighBehavesLike.Win32.PWSZbot.cz
McAfeePolyPatch-UPX
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.LdPinch.Win32.29471
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.36802.hmX@aipfOLei
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BPMF
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Razy-9935848-0
KasperskyTrojan-PSW.Win32.LdPinch.hij
BitDefenderGen:Variant.Fugrafa.311994
NANO-AntivirusTrojan.Win32.LdPinch.cqjkmt
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bfc4ce
EmsisoftGen:Variant.Fugrafa.311994 (B)
F-SecureTrojan.TR/Spy.Zbot.gdb
VIPREGen:Variant.Fugrafa.311994
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.moderate.ml.score
SophosTroj/Zbot-GYX
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojan/PSW.LdPinch.adnc
GoogleDetected
AviraTR/Spy.Zbot.gdb
VaristW32/Trojan.YDPT-8907
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BFP@54u2z9
ArcabitTrojan.Fugrafa.D4C2BA
ZoneAlarmTrojan-PSW.Win32.LdPinch.hij
MicrosoftTrojan:Win32/Zbot.HBAI!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.UPX.R643574
Acronissuspicious
VBA32TrojanPSW.Pinch
ALYacGen:Variant.Fugrafa.311994
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.FakePDF/ICON!1.9C28 (CLASSIC)
YandexTrojan.PWS.LdPinch!vqWY8FswHvg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/ZBot.GDB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Fugrafa.311994 (B)?

Fugrafa.311994 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment