Malware

About “Graftor.709712 (B)” infection

Malware Removal

The Graftor.709712 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.709712 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Graftor.709712 (B)?


File Info:

name: B5368FA42A0EFF0B9CC2.mlw
path: /opt/CAPEv2/storage/binaries/287dd2fb5a4a84f33b417fb1338181cb72d9200635d8ed7db07651c92da8d2df
crc32: 66CD5CA6
md5: b5368fa42a0eff0b9cc28dac781d0506
sha1: ccb1a822e9d1ed0f3a9445ff90893b1cd974e0db
sha256: 287dd2fb5a4a84f33b417fb1338181cb72d9200635d8ed7db07651c92da8d2df
sha512: 7aa7ce8c2aabe74bd343ad1abcb1a168f5ef220f3e15c817c5d1a31183cc32fb0042ca33baf4fa682c051d971f92cc3e0ba89ccfdd1494ab7aca4f018c043d46
ssdeep: 49152:OKjgSjO85lxE9SLgv6YbHXeTZaqdwk0c05HGiI+9:hE0gv6YbHOYqdwkLcHHI+9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BA5D002F352C0F1D34D097019B6D73A5970A6B64E30DA8BE7F5DDB86C332A19A7225E
sha3_384: f6f3f7ff680b28f63d628ab17c0063b2f87ed902ae95e26d3d77b1241d7d2ba29a824bf6b1c7cae4d39671dec335bacf
ep_bytes: 558bec6aff6810bb5c00688c314b0064
timestamp: 2021-08-19 15:50:18

Version Info:

CompanyName:
FileDescription: 请勿外传,发现封卡
FileVersion: 1.93
InternalName:
LegalCopyright:
OriginalFilename:
ProductName: 最新京东奶抢1.93
ProductVersion:
Translation: 0x0804 0x04b0

Graftor.709712 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.709712
FireEyeGeneric.mg.b5368fa42a0eff0b
ALYacGen:Variant.Graftor.709712
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.42a0ef
BitDefenderThetaGen:NN.ZexaF.34114.@r0@aujoReab
CyrenW32/Trojan.CLL.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H09AB22
ClamAVWin.Trojan.Agent-583204
BitDefenderGen:Variant.Graftor.709712
Ad-AwareGen:Variant.Graftor.709712
SophosGeneric PUA MM (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Graftor.709712 (B)
APEXMalicious
GDataWin32.Trojan.PSE.5LSHNI
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASCommon.FA
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!B5368FA42A0E
VBA32BScope.Trojan.StartPage
MalwarebytesTrojan.MalPack.FlyStudio
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazra/iHUL4t9j3x2L45/qgqk)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.65CA!tr
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Graftor.709712 (B)?

Graftor.709712 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment