Malware

About “Graftor.372539” infection

Malware Removal

The Graftor.372539 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.372539 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Graftor.372539?


File Info:

name: CE77F54E242025816355.mlw
path: /opt/CAPEv2/storage/binaries/d8c3f2ff783cc04ca179cceee0d951674927a5e65e4d60d7b62d73183899e1f0
crc32: 953F349D
md5: ce77f54e242025816355e332952de1bb
sha1: 2285b7bf86f147a085f06ea42996ea0a0bd6e16a
sha256: d8c3f2ff783cc04ca179cceee0d951674927a5e65e4d60d7b62d73183899e1f0
sha512: f7da8361dc5cd4ff6ece37fc79d4532a81e60bfd780e4468f4d9b761dca0cb57d337f925e1da9ae86cd7731c51dc10a4abd69bcd5a76c1e3dafa551b38858e6e
ssdeep: 49152:gKe+YtRcfmgsieYTUamo98K8CLcE0grvhoY1ug:qxteqcHc1g9oYt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162061700E640C129D8E761BDAAED6128681CEDDF171391C7718726EBAA35EFC3D3419E
sha3_384: 050371bd7a0d9042237433b5e883703d70deab776098081c9fc763dcaadef5d0d6b4a95e0a5c0718e2df10f48b37617f
ep_bytes: e97c511400e947520a00e9f2160600e9
timestamp: 2017-02-26 08:13:02

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: testproj.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: testproj.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Graftor.372539 also known as:

Elasticmalicious (moderate confidence)
DrWebTrojan.Click3.23743
MicroWorld-eScanGen:Variant.Graftor.372539
FireEyeGeneric.mg.ce77f54e24202581
ALYacGen:Variant.Graftor.372539
VIPREGen:Variant.Graftor.372539
K7AntiVirusTrojan ( 004fa1541 )
BitDefenderGen:Variant.Graftor.372539
K7GWTrojan ( 004fa1541 )
Cybereasonmalicious.e24202
ArcabitTrojan.Graftor.D5AF3B
SymantecTrojan.Kasperbogi
ESET-NOD32a variant of Win32/Kasperagent.E.gen
APEXMalicious
ClamAVWin.Malware.Johnnie-9958146-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Agent.elzanb
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
Ad-AwareGen:Variant.Graftor.372539
ZillyaTrojan.Snojan.Win32.15
McAfee-GW-EditionGenericR-JIU!CB336CEA05EF
EmsisoftTrojan-PSW.Agent (A)
JiangminTrojan.Generic.hdejo
GoogleDetected
AviraTR/KAgent.rwsih
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.2D
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.372539
AhnLab-V3Trojan/Win32.RL_DOTHETUK.R331398
McAfeeGenericR-JIU!CB336CEA05EF
VBA32Backdoor.Spy
MalwarebytesMalware.AI.1573129850
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.12026223
YandexTrojan.GenAsa!GEr0bUMG0VM
IkarusTrojan.Agent
FortinetW32/Agent.YJA!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Graftor.372539?

Graftor.372539 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment