Malware

Graftor.312353 (file analysis)

Malware Removal

The Graftor.312353 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.312353 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to modify proxy settings

How to determine Graftor.312353?


File Info:

name: 9B3B31C88DEABAA52C0E.mlw
path: /opt/CAPEv2/storage/binaries/a7805ce6a9cf270dd6c64b4326143436fbcdda325dc80272e9711132ae328ad2
crc32: 0D17F9C0
md5: 9b3b31c88deabaa52c0e79abcf08a25d
sha1: b8b5385bae0d6db92067551519638069cc7de6e1
sha256: a7805ce6a9cf270dd6c64b4326143436fbcdda325dc80272e9711132ae328ad2
sha512: 6368cf8a9084fb69505eecfd747ecf3a9dcdf704c947c807f259a17b047aabb56c0491f769aa261bf45a621ea092af1af76b522a035b34d9f9ee33d18d2160d2
ssdeep: 768:tZRJimLHpvfRJxRlFGuliTh1PcPW/M9zh:tZRJFLrjcy6PTEzh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163E24A85DA5CD5C6E85E2C70728EE7771E35AFE7050C6A729FB1EE194853380FA2420E
sha3_384: 1c724eaf076854338087d497f69612f985bd8c780e1e7adce04eb11b5b6a110a0ece157f75be3f5100a01e80b8184fb5
ep_bytes: 558bec6aff68b040400068903f400064
timestamp: 2012-07-24 02:54:56

Version Info:

0: [No Data]

Graftor.312353 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.312353
ALYacGen:Variant.Graftor.312353
CylanceUnsafe
Cybereasonmalicious.88deab
SymantecBackdoor.Blavur
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Small.NMV
APEXMalicious
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyVHO:Trojan.Win32.BlueTraveller.gen
BitDefenderGen:Variant.Graftor.312353
NANO-AntivirusTrojan.Win32.Agent.wvebs
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Graftor.312353
EmsisoftGen:Variant.Graftor.312353 (B)
ComodoTrojWare.Win32.Agent.swgg@4sbubk
DrWebBackDoor.RemShell.2
VIPREGen:Variant.Graftor.312353
FireEyeGeneric.mg.9b3b31c88deabaa5
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.312353
JiangminTrojan.Script.autq
AviraHEUR/AGEN.1223792
Antiy-AVLTrojan/Generic.ASMalwS.151
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C81957
McAfeeGenericRXAA-AA!9B3B31C88DEA
MAXmalware (ai score=84)
VBA32Backdoor.RemShell
MalwarebytesMalware.AI.1575704587
YandexTrojan.GenAsa!0tHzCxwlzrc
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Small.NNG!tr
BitDefenderThetaGen:NN.ZexaF.34806.cmY@aufhaFl
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Graftor.312353?

Graftor.312353 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment