Malware

Graftor.1327 malicious file

Malware Removal

The Graftor.1327 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.1327 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 0.0.0.0:17525, :0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Clears web history

Related domains:

www.france-facebook.com

How to determine Graftor.1327?


File Info:

crc32: F9D59ADF
md5: 5d17776a4fd84d97c0cbd5d418be6afd
name: 5D17776A4FD84D97C0CBD5D418BE6AFD.mlw
sha1: b4ee4da3c32039cb5e81a394f3e086bbacb9da33
sha256: ba1aa35062fcc0b5a8a47a3d1bc78276b90a7eb5caaa9d5b513fe9b507b3834c
sha512: 7b81fe2e483148bc890481ed6ec29c7295c02979566e633e9e53e4fa15f1bbea8669da3f8d6522e69cce41b112e7372f97d55ba4439b2f7d359079b427c88258
ssdeep: 3072:0XUm6enMctZyWd/com4HZmoVTtNuFSdz1sIR8YmEXY8zMbRcrAO1tRG:K61KZyw/OGZLZtNuFSt1sYmEI8zicAOI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2010 Mark Russinovich
InternalName: Process Explorer
FileVersion: 14.01
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2010 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 14.01
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Graftor.1327 also known as:

BkavW32.AIDetect.malware2
DrWebBackDoor.IRC.Bot.872
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.1327
CylanceUnsafe
ZillyaDropper.Injector.Win32.600
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Win32/Injector.aadd70d6
Cybereasonmalicious.a4fd84
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
AvastWin32:Inject-AMO [Trj]
ClamAVWin.Trojan.CeeInject-2
KasperskyTrojan-Dropper.Win32.Injector.hrm
BitDefenderGen:Variant.Graftor.1327
NANO-AntivirusTrojan.Win32.Inject.gbiqn
MicroWorld-eScanGen:Variant.Graftor.1327
TencentMalware.Win32.Gencirc.114b6fb3
Ad-AwareGen:Variant.Graftor.1327
SophosMal/Zbot-EO
ComodoMalware@#ztwk2nnzo8cp
BitDefenderThetaGen:NN.ZexaF.34170.nq1@amXjIhki
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FAKEAV.CFA
McAfee-GW-EditionPWS-Zbot.gen.bbf
FireEyeGeneric.mg.5d17776a4fd84d97
EmsisoftGen:Variant.Graftor.1327 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Dropper]/Win32.Injector
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-CeeInject
GDataGen:Variant.Graftor.1327
AhnLab-V3Trojan/Win32.HDC.C103892
Acronissuspicious
McAfeePWS-Zbot.gen.bbf
MAXmalware (ai score=99)
VBA32TrojanDropper.Injector
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.CFA
YandexTrojan.Injector!31kX1/cQA1I
IkarusVirus.Win32.CeeInject
FortinetW32/Injector.JKV!tr
AVGWin32:Inject-AMO [Trj]
Paloaltogeneric.ml

How to remove Graftor.1327?

Graftor.1327 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment