Malware

Graftor.380721 (file analysis)

Malware Removal

The Graftor.380721 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.380721 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

discriminate.blockey.ru

How to determine Graftor.380721?


File Info:

crc32: 0338DA32
md5: 25a5f3734594d9d4bec52741a1857010
name: 25A5F3734594D9D4BEC52741A1857010.mlw
sha1: 788c179e1c9af906511cef024ab70818274ec163
sha256: dc6491d0e79658e8d6cf6afe402311dc1f0a78824bd2d4ee9b30fa3d106bc62d
sha512: 79e51d2ab7de5ad8f699898dea58902ca9e1dc22a2b80448dc03e9b6210dfea769d92608a19b65afd026245c32817ac63c56aafa7f5f6c87287db3314c8af5e3
ssdeep: 6144:SykG+o7aZIJtZZZZZZZZZZZZZZZZZZZZZZI6nf7:Sk+o7+OTnf7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Preloaded Version
InternalName: Preloaded Version
FileVersion: 41.34.22.68
CompanyName: Preloaded Version
LegalTrademarks: Preloaded Version
ProductName: Preloaded Version
ProductVersion: 38.45.27.68
FileDescription: Preloaded Version
OriginalFilename: Preloaded Version
Translation: 0x0000 0x04e4

Graftor.380721 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.380721
FireEyeGeneric.mg.25a5f3734594d9d4
CAT-QuickHealAdware.Dataric.A5
ALYacGen:Variant.Graftor.380721
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Variant.Graftor.380721
K7GWUnwanted-Program ( 0050ffde1 )
K7AntiVirusUnwanted-Program ( 0050ffde1 )
CyrenW32/S-318640c0!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyTrojan.Win32.Agent.nfacyh
AlibabaTrojanDownloader:Win32/Tovkater.31dda6bb
NANO-AntivirusTrojan.Win32.Agent.epxykt
TencentMalware.Win32.Gencirc.10b59001
Ad-AwareGen:Variant.Graftor.380721
SophosGeneric PUA HI (PUA)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.G@72ttyk
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2420
TrendMicroTROJ_GEN.R002C0PB221
McAfee-GW-EditionPUP-FZZ
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Suspicious PE – Installer
JiangminTrojanDownloader.Generic.awgi
MaxSecureAdware.not-a-virus.Win32.Adwre.Generic_194538
AviraADWARE/InstMonster.Gen7
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Agent
MicrosoftSoftwareBundler:Win32/InstallMonster
ArcabitTrojan.Graftor.D5CF31
ZoneAlarmTrojan.Win32.Agent.nfacyh
GDataGen:Variant.Graftor.380721
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.InstallMonster.R202692
McAfeePUP-FZZ
VBA32Trojan.Agent
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaPUP/DownloadAssistant
ESET-NOD32Win32/TrojanDownloader.Tovkater.AQ
TrendMicro-HouseCallTROJ_GEN.R002C0PB221
RisingDownloader.Tovkater!1.ABF6 (CLASSIC)
YandexTrojan.Agent!aV6B4m/swv0
IkarusTrojan-Downloader.Win32.Tovkater
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.F4BA0!tr
AVGWin32:AdwareSig [Adw]
Qihoo-360Win32/Trojan.6f3

How to remove Graftor.380721?

Graftor.380721 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment