Malware

What is “Graftor.27148”?

Malware Removal

The Graftor.27148 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.27148 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Graftor.27148?


File Info:

name: 96A56D61E8D31A3DC997.mlw
path: /opt/CAPEv2/storage/binaries/46e384091fe42233ea82ac531b40ca50ed8c0bdf60b27db95fde40e381165d2a
crc32: 1E4FB5FB
md5: 96a56d61e8d31a3dc9978e3ba0f3a3b2
sha1: 09f08e2929b7b5b0649504718fab0a2cf7706938
sha256: 46e384091fe42233ea82ac531b40ca50ed8c0bdf60b27db95fde40e381165d2a
sha512: c21339514587f1d4b037b4034c06ebf0bb9d965c8ce25272e23413a8932d8ac3fc82f5c59df9df8fdd8a6c6a59357c5039c6ba8c49e2526c96d56e3132273142
ssdeep: 6144:2poSsYgjGEQBD98TbzCNIgAYkpHpzm0nDRztN2lfuu:2poSPEQBD2nzqwNRD5tN2Juu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DD3423BF74794E0ECBA0F172075E91EE3E40AEA5499C380631BDD254B7627C45CB26E8
sha3_384: 9ed79561dc893bcd63690f649de2e27b391513eafa08ddd0efc5b247cf91c2e69b153f98995ea46eea8ae7443fb66c86
ep_bytes: 60be15a040008dbeeb6fffff5789e58d
timestamp: 2012-05-25 12:14:04

Version Info:

0: [No Data]

Graftor.27148 also known as:

LionicTrojan.Win32.Generic.lxMa
tehtrisGeneric.Malware
DrWebTrojan.PWS.Panda.547
MicroWorld-eScanGen:Variant.Graftor.27148
FireEyeGeneric.mg.96a56d61e8d31a3d
ALYacGen:Variant.Graftor.27148
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.2302
SangforTrojan.Win32.Graftor.frxK
K7AntiVirusTrojan ( 003a34081 )
K7GWTrojan ( 003a34081 )
Cybereasonmalicious.1e8d31
BitDefenderThetaGen:NN.ZexaF.34592.omGfaqJnATc
VirITTrojan.Win32.Generic.BDIT
CyrenW32/Downloader.NVVL-2218
SymantecSecurityRisk.Dropper
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Injector.RWF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-22080
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.27148
NANO-AntivirusTrojan.Win32.Winlock.sjhvv
SUPERAntiSpywareTrojan.Agent/Gen-Gimemo
AvastWin32:Downloader-OPK [Trj]
TencentWin32.Trojan.Dloader.cfbh
Ad-AwareGen:Variant.Graftor.27148
SophosMal/Inject-CEE
ComodoTrojWare.Win32.Spy.Zbot.EDND@4pp6h3
VIPREGen:Variant.Graftor.27148
TrendMicroTSPY_DLOADER.SMK
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.27148 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Gimemo.cek
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.644
MicrosoftVirTool:Win32/CeeInject.gen!HF
ViRobotTrojan.Win32.A.Gimemo.235008.B
GDataGen:Variant.Graftor.27148
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gimemo.R29339
McAfeeGenericRXAA-AA!96A56D61E8D3
VBA32Hoax.Gimemo
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTSPY_DLOADER.SMK
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!Z5bs7LOfKyg
IkarusTrojan.Win32.Ransom
FortinetW32/Zbot.ADR!tr
AVGWin32:Downloader-OPK [Trj]
PandaTrj/PurePack.a
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Graftor.27148?

Graftor.27148 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment