Malware

Graftor.557793 information

Malware Removal

The Graftor.557793 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.557793 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
4.tcp.ngrok.io

How to determine Graftor.557793?


File Info:

crc32: C4C12129
md5: 6cf07ab2ff64200e8cd38602d14bc566
name: 6CF07AB2FF64200E8CD38602D14BC566.mlw
sha1: 74edddc5fa816ecd47bb0a90b4ed605e1b8e8e6b
sha256: 7a5ea108c883639b28770a677217474e15e8e26a141b13cefd59100f72c3a598
sha512: a47d91fb8c9f3edeb18897989f93ff8e5a2f90a4fa19f512983512238597988e5b490ebd1595dcd0aaf294c222a51d3c10da5ea013bccb0948e538ee00b8bbe1
ssdeep: 24576:3hJuYLZOb7wDVCWXZF4iZ1mbr8XoR/+HfEH7WQsemsvLYuQX4:3hF4k8H7lIfEbW2vvLXQX4
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Graftor.557793 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052a8371 )
Elasticmalicious (high confidence)
ClamAVWin.Malware.Agen-9821312-0
ALYacGen:Variant.Graftor.557793
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Graftor.557793
K7GWTrojan ( 0052a8371 )
Cybereasonmalicious.2ff642
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Bladabindi
MicroWorld-eScanGen:Variant.Graftor.557793
Ad-AwareGen:Variant.Graftor.557793
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34110.kHW@aS2N@of
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.6cf07ab2ff64200e
EmsisoftGen:Variant.Graftor.557793 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Graftor.557793
AhnLab-V3Malware/Gen.Generic.C3031443
Acronissuspicious
McAfeeGenericRXPU-WH!6CF07AB2FF64
MAXmalware (ai score=88)
VBA32Trojan.Tiggre
YandexTrojan.GenAsa!VWnMADV1R3Q
IkarusTrojan.Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application

How to remove Graftor.557793?

Graftor.557793 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment