Malware

About “Graftor.699947” infection

Malware Removal

The Graftor.699947 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.699947 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

config.bang5tao.top
s19.cnzz.com

How to determine Graftor.699947?


File Info:

crc32: 4FFDF084
md5: 34997fabcda0f0df67c07cfa5a182c5e
name: upload_file
sha1: 8afd295b03ad68a01a87448c1406a3f55406da8a
sha256: 0baecdbef7514330ccc51e80870caf319dca8457a490d7af3e5829adb20d906c
sha512: ab6c2192b250d6477e0596d73f054723538597cb9cc7b57e7aa848e5688ca019d34c13fbd0be55fa4d5b5d65491ba86e9f2113aa0826c15e59e7579111fe4890
ssdeep: 98304:nZn7fyEX5cbnxeMnNQ6hyj2Z7zuZNxI+NhBpi5hsh:Zr5gVnVyj2Z7KNxIIgrW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) BbSeePic Inc 2018.
InternalName: x8d1dx8d1dx770bx56fex5b89x88c5x7a0bx5e8f
FileVersion: 3.0.2.3
CompanyName: x8d1dx8d1dx770bx56fe
ProductName: x8d1dx8d1dx770bx56fe
ProductVersion: 3.0.2.3
FileDescription: x8d1dx8d1dx770bx56fex5b89x88c5x7a0bx5e8f
OriginalFilename: BbSeePicInst.exe
Translation: 0x0804 0x04b0

Graftor.699947 also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojan.MauvaiseRI.S5257886
ALYacTrojan.Downloader.Chindo
CylanceUnsafe
ZillyaDownloader.Chindo.Win32.787
K7AntiVirusTrojan-Downloader ( 00532c7f1 )
BitDefenderGen:Variant.Graftor.699947
K7GWTrojan-Downloader ( 00532c7f1 )
Cybereasonmalicious.bcda0f
TrendMicroTROJ_GEN.R002C0DIS20
CyrenW32/Chindo.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Chindo.AD
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.DownLoad4.fdxxpb
AegisLabTrojan.Win32.Generic.4!c
EmsisoftGen:Variant.Graftor.699947 (B)
ComodoMalware@#na71r626v22p
F-SecureHeuristic.HEUR/AGEN.1115848
DrWebTrojan.DownLoad4.11494
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.34997fabcda0f0df
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Chindo
AviraHEUR/AGEN.1115848
MAXmalware (ai score=98)
Antiy-AVLTrojan[Downloader]/Win32.Agent
MicrosoftPUA:Win32/CoinMiner
ArcabitTrojan.Graftor.DAAE2B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Graftor.699947
CynetMalicious (score: 85)
McAfeeArtemis!34997FABCDA0
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DIS20
RisingAdware.Agent!1.BC68 (CLASSIC)
eGambitUnsafe.AI_Score_99%
FortinetW32/Chindo.H!tr
BitDefenderThetaGen:NN.ZedlaF.34254.vu!@ayOQH5hj
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Graftor.699947?

Graftor.699947 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment