Malware

What is “Fugrafa.32248”?

Malware Removal

The Fugrafa.32248 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Fugrafa.32248 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects VirtualBox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Collects information to fingerprint the system

How to determine Fugrafa.32248?


File Info:

name: F59823B6AD3F7B3623E7.mlw
path: /opt/CAPEv2/storage/binaries/4ab875129be9a47815be0ac37737238a377a6712b32aaaefcf1ff92b677944e9
crc32: 65D3D564
md5: f59823b6ad3f7b3623e746544a49ec17
sha1: 59f0e963ef1a2229587c8e820f4018ab5ef755b1
sha256: 4ab875129be9a47815be0ac37737238a377a6712b32aaaefcf1ff92b677944e9
sha512: bf81eb3fccd132f0af306b2c380b8dfe324ea42df7f374aa3da560dabcef55bc3f3623ca4cef975dd5af1bcc57054f668901dc73775f36e1e73758944080f512
ssdeep: 24576:/Y+8kxpvVP43bTemCIup7On+gezmGc7J+Nhv:/YjwVg33jsp7cWcNs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19C05F101F681D532CB61303091ACA7B7093E7C244F25EAD773DD14A9AFA42E14BBDB66
sha3_384: 42481275d1573154deb8c0e4a15c4e790f3b0f0a1ae41c014661aaa7c42bc28defb008cb2516c7bd4356dcb405f3e90a
ep_bytes: e835050000e974feffff558bec81ec24
timestamp: 2021-12-09 17:53:23

Version Info:

0: [No Data]

Fugrafa.32248 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ALYacGen:Variant.Fugrafa.32248
BitDefenderGen:Variant.Fugrafa.32248
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.DBI potentially unsafe
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.SpeedBit.vho
NANO-AntivirusRiskware.Win32.SpeedBit.ixfini
MicroWorld-eScanGen:Variant.Fugrafa.32248
Ad-AwareGen:Variant.Fugrafa.32248
EmsisoftGen:Variant.Fugrafa.32248 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.f59823b6ad3f7b36
SophosMal/Behav-010
IkarusTrojan.Hijacker
GDataGen:Variant.Fugrafa.32248
JiangminHeur:Trojan/AntiVM
AviraTR/Hijacker.Gen
MAXmalware (ai score=82)
ArcabitTrojan.Fugrafa.D7DF8
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win32.RL_Generic.R360901
Acronissuspicious
McAfeeGenericRXKS-KA!F59823B6AD3F
VBA32BScope.Adware.SpeedBit
CylanceUnsafe
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazriLubGt5itzx49Cq/AJITR)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_83%
BitDefenderThetaGen:NN.ZexaF.34084.0yW@aWU!H!fi
Cybereasonmalicious.6ad3f7
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Fugrafa.32248?

Fugrafa.32248 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment