Malware

About “Graftor.701687 (B)” infection

Malware Removal

The Graftor.701687 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.701687 (B) virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Graftor.701687 (B)?


File Info:

name: 99E4210AA42A8466CDDB.mlw
path: /opt/CAPEv2/storage/binaries/0042723d6989fe416f9555faff561da3086e2013da9d19b9c7294b3b3d271424
crc32: 445DD4A2
md5: 99e4210aa42a8466cddb9d90ebb5f89d
sha1: 58f60120d8adac420914478f84c5d2ffb4559c8c
sha256: 0042723d6989fe416f9555faff561da3086e2013da9d19b9c7294b3b3d271424
sha512: 8c1c245f514cd4c460950a69a0ab1f4214dcfcedb2ba52026356163c5ed9939c780ebc9f312496a58780f2be69326e3b832b8c0d872e858408b7a16d93187647
ssdeep: 384:aeMigwsE1QEgwsEoVx5rMhXxYpC9UaaVR5JPOrLIrZ61eE:aeMigwlgwExZMhhb9jmhPOrmZ60E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150C353299BE955B6E3B7CA7E85F141C6B822B0623F019DCE84C643850863F96DDF074E
sha3_384: 6497e9dbb72f9ffe0ecaf75bedc9adbc9b3083b46f227a9f7c42ae59d27cff2bd49e0c4550adb46a27cc8376214fef5d
ep_bytes: 57565351e857feffffc3cccccccccccc
timestamp: 1973-02-28 09:38:41

Version Info:

0: [No Data]

Graftor.701687 (B) also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Graftor.701687
ClamAVWin.Downloader.Upatre-9939183-0
CAT-QuickHealTrojan.GenericCS.S26719226
McAfeeGenericRXAA-AA!99E4210AA42A
MalwarebytesTrojan.Upatre.Generic
ZillyaDownloader.Upatre.Win32.70333
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0052964f1 )
K7AntiVirusTrojan ( 0052964f1 )
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Waski.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
ZonerTrojan.Win32.26163
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.efj
BitDefenderGen:Variant.Graftor.701687
NANO-AntivirusTrojan.Win32.MlwGen.dewlww
AvastWin32:Agent-AULS [Trj]
TencentTrojan-Downloader.Win32.Upatre.fa
EmsisoftGen:Variant.Graftor.701687 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Upatre.87
VIPREGen:Variant.Graftor.701687
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Infected.cz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.99e4210aa42a8466
SophosTroj/HkMain-AZ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.1IBQSRA
JiangminTrojanDropper.Dapato.pdf
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Dropper]/Win32.Dapato
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
ArcabitTrojan.Graftor.DAB4F7
ViRobotTrojan.Win32.U.Downloader.22528
ZoneAlarmTrojan-Downloader.Win32.Upatre.efj
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
GoogleDetected
AhnLab-V3Downloader/Win.Upatre.R564299
BitDefenderThetaGen:NN.ZexaF.36132.hmX@a00ayUl
ALYacGen:Variant.Graftor.701687
MAXmalware (ai score=85)
VBA32Hoax.Cryptodef
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!8.184 (TFE:2:1rA9VijPqKK)
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
DeepInstinctMALICIOUS

How to remove Graftor.701687 (B)?

Graftor.701687 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment