Malware

Graftor.621507 (file analysis)

Malware Removal

The Graftor.621507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.621507 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Graftor.621507?


File Info:

name: F0B313C9BFF76F5F8B2B.mlw
path: /opt/CAPEv2/storage/binaries/c239993af9ba46209d4c631578159e632658c5647130caee322ca7a27c3cd034
crc32: 8947AC4A
md5: f0b313c9bff76f5f8b2b05675f9c71e0
sha1: f7c67e12e14ad186a26b3f37844fd481ad691a45
sha256: c239993af9ba46209d4c631578159e632658c5647130caee322ca7a27c3cd034
sha512: e0a4e6c3625f7fe106d8faee5b5d5121be3a71c9577547b40d9b4591108ea98f388d3e85488ae1d615fc5505ca43358ee371d8be572c0fd2a7cd59aa7e33a2e6
ssdeep: 6144:F5gITy07RGPOqhezSA+j/o9ZMUPSGBJDtGvBSxSV61:F5gITyhPOd9iGPDtFxp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10694E021FA40C072C2D3697C5DD883614C3AF5305CF6A80377A96A6A7AB07D27AF7365
sha3_384: edcaea0ad0c44b2f415794e6349ecb75974321b39acbeaf0d3f9a193ee4bbc7ebc1cafa143d3c04570277c8f153923c1
ep_bytes: e8c0640000e989feffff8bff558bec83
timestamp: 2013-04-12 15:53:38

Version Info:

CompanyName: SoftWall Ent.
FileDescription: WMI Performance Adapter Maintenance Utility
FileVersion: 4.3.5.2
InternalName: perfutil
LegalCopyright: Copyright (C) 2006-2012 - SoftWall Ent.
OriginalFilename: perfutil
ProductName: WMI Performance Adapter Maintenance Utility
ProductVersion: 4.3.5.2
Translation: 0x1009 0x04b0

Graftor.621507 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f0b313c9bff76f5f
McAfeePolyPatch-UPX
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.120330
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/LockScreen.33239d36
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
SymantecTrojan.Ransomlock.G
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.621507
NANO-AntivirusTrojan.Win32.Panda.crknsk
MicroWorld-eScanGen:Variant.Graftor.621507
AvastWin32:LockScreen-VZ [Trj]
RisingSpyware.Zbot!8.16B (CLOUD)
Ad-AwareGen:Variant.Graftor.621507
EmsisoftGen:Variant.Graftor.621507 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.PWS.Panda.2401
VIPRETrojan.Win32.Reveton.b!ag (v)
TrendMicroTROJ_FRS.0NA103BL20
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
SophosMal/Generic-S + Mal/EncPk-AKK
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.621507
JiangminTrojanSpy.Zbot.dhha
eGambitGeneric.PSW
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.HeurC.KVM007.a.(kcloud)
ArcabitTrojan.Graftor.D97BC3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
AhnLab-V3Trojan/Win32.LockScreen.R67778
Acronissuspicious
BitDefenderThetaAI:Packer.A3BCEECC21
ALYacGen:Variant.Graftor.621507
TACHYONTrojan-Spy/W32.ZBot.413184.U
VBA32TrojanSpy.Zbot
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
TencentWin32.Trojan.Generic.Ecjr
YandexTrojan.GenAsa!oebaOQyNah8
IkarusWin32.LockScreen
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BA!tr
WebrootTrojan.Dropper.Gen
AVGWin32:LockScreen-VZ [Trj]
PandaTrj/CI.A

How to remove Graftor.621507?

Graftor.621507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment