Malware

Graftor.726428 malicious file

Malware Removal

The Graftor.726428 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.726428 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

www.baidu.com

How to determine Graftor.726428?


File Info:

crc32: A76FFAD1
md5: a2fab026e0149b34704ba5f68ed62311
name: A2FAB026E0149B34704BA5F68ED62311.mlw
sha1: 91a37f9e1f00b742b3ab92804d06f88d1bb6fc46
sha256: 4cc697ff3018d3d083ad8d7178d9baebc9b320ac825f30e4d095fbfc326ce1b0
sha512: 5c259ea03601f911454bfea2f48929b55020fa1efde74343e2a788dcb4bc678c3d9c76a7137fbbf887e365ecc783fbaea1f23156fc8d433a015491a181b74a69
ssdeep: 24576:uaY1OAGTMUPhOPpXQb84aWZdUEBT+P8HbobiOL8hNIhXwhQtLBbeqvYl+G3rFBx:Bdl0XMUE84CdhXaMtfaFBx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x795ex57df x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x795ex57df
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x795ex57dfx9003x8dd1x5427x5c11x5e74x8f85x52a9
ProductVersion: 1.0.0.0
FileDescription: x795ex57dfx9003x8dd1x5427x5c11x5e74x8f85x52a91.0
Translation: 0x0804 0x04b0

Graftor.726428 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.726428
FireEyeGeneric.mg.a2fab026e0149b34
ALYacGen:Variant.Graftor.726428
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin64:Trojan-gen
ClamAVWin.Malware.Flystudio-9752414-0
BitDefenderGen:Variant.Graftor.726428
Paloaltogeneric.ml
RisingHackTool.GameHack!1.B2A6 (CLOUD)
Ad-AwareGen:Variant.Graftor.726428
EmsisoftGen:Variant.Graftor.726428 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.th
MaxSecureDropper.Dinwod.frindll
SophosGeneric PUA JB (PUA)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Graftor.DB159C
GDataWin32.Application.FlyStudio.F
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!A2FAB026E014
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34590.Vr1@aWB4U@fb
AVGWin64:Trojan-gen
Cybereasonmalicious.6e0149

How to remove Graftor.726428?

Graftor.726428 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment