Malware

Graftor.832804 (file analysis)

Malware Removal

The Graftor.832804 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.832804 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs an hook procedure to monitor for mouse events
  • Sniffs keystrokes

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Graftor.832804?


File Info:

crc32: DF9385AB
md5: d946d7bc4a08466cee2be5a8888b7dd0
name: 112bit.exe
sha1: bb342f777aaefc07268d3913cbbef9f9c370c414
sha256: a3f8ea350164c10a6b6dd986814d09feea479f8ed5389065c660257145a4218e
sha512: 8a164ec6556986ed15a677e16f2eb7f62f42fa6eb81fd818856026b84e1242434b62cd861383be85d2bb3bea2bf7bdbe2ebab39263fa6c56f15614477e742455
ssdeep: 24576:vSTYNH/sXisC8K3jVQNG+j6W5IjH+lysdEReeCei5+Th7kx5UL7gmbFLnL+joO:VHMiTG5Ij+lFqCerh7kxugeTLe
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Graftor.832804 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.832804
FireEyeGeneric.mg.d946d7bc4a08466c
CAT-QuickHealTrojanspy.Solmyr
McAfeeGenericRXAA-FA!D946D7BC4A08
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 00569be91 )
BitDefenderGen:Variant.Graftor.832804
K7GWTrojan ( 00569be91 )
Cybereasonmalicious.c4a084
TrendMicroTROJ_GEN.R002C0WJL20
BitDefenderThetaAI:Packer.BE1F1CAB1E
CyrenW32/Downloader.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Solmyr.gen
AlibabaTrojanSpy:Win32/Solmyr.d5c6a168
RisingBackdoor.Agent!1.CD8B (CLASSIC)
Ad-AwareGen:Variant.Graftor.832804
ComodoMalware@#1v09tt4z7rkw4
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader35.3673
ZillyaTrojan.Solmyr.Win32.48
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Graftor.832804 (B)
SentinelOneDFI – Malicious PE
JiangminTrojanSpy.Solmyr.r
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Ymacco.AAA3
ArcabitTrojan.Graftor.DCB524
ZoneAlarmHEUR:Trojan-Spy.Win32.Solmyr.gen
GDataGen:Variant.Graftor.832804
CynetMalicious (score: 100)
VBA32BScope.Trojan.CMY3U
ESET-NOD32a variant of Win32/Agent.ACBZ
YandexTrojan.Agent!kelSwssSyeo
MAXmalware (ai score=88)
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.ACBZ!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Spy.87f

How to remove Graftor.832804?

Graftor.832804 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment