Malware

Graftor.888746 (B) information

Malware Removal

The Graftor.888746 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.888746 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Graftor.888746 (B)?


File Info:

name: FDDB1C4E4BA4CDFFF22A.mlw
path: /opt/CAPEv2/storage/binaries/04cb73ef2dd09d4fc987fea6381da4eb4950a33776cd05a590589c0da028e01c
crc32: 0E89447E
md5: fddb1c4e4ba4cdfff22a76249629501c
sha1: b135b2b37bef3cef2362ffabead6cca02382810b
sha256: 04cb73ef2dd09d4fc987fea6381da4eb4950a33776cd05a590589c0da028e01c
sha512: 29f1d191906140994305fcc55fe25f25913b0dda40b9af7896ba1f7fdc71f07233aa489f9242db747ee343cc723bc36a6a3a0aada4234c89439a83ba76bb2a45
ssdeep: 24576:8lcLNdlWzkvMyA55atGzwlKXbmkzT5TsAP9/DPfmzPPoVPFPPiPP+J3Dkigjl39F:8lcLf1kyAfyKXhhpm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A45BE02B68280F2C285293105F6A77ADB358F556F25CB83D764FE6D7D33281EA3711A
sha3_384: 1d0e4fe2b497fc85f67c3a882d8f145baa619e3d140b455e054e71ab939c7cfe97801260f152096e7da40667ee91c968
ep_bytes: 558bec6aff6868954f0068b87d490064
timestamp: 2021-12-07 13:00:24

Version Info:

FileVersion: 1.0.0.0
FileDescription: 权重助手
ProductName: 权重助手
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 权重助手
Translation: 0x0804 0x04b0

Graftor.888746 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.888746
FireEyeGeneric.mg.fddb1c4e4ba4cdff
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
K7GWAdware ( 004b87ea1 )
Cybereasonmalicious.e4ba4c
BitDefenderThetaGen:NN.ZexaF.34084.or0@ayiyzKib
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AC potentially unwanted
ClamAVWin.Malware.Generic-9820446-0
KasperskyHEUR:Trojan.Win32.Kolovorot.gen
BitDefenderGen:Variant.Graftor.888746
Ad-AwareGen:Variant.Graftor.888746
EmsisoftGen:Variant.Graftor.888746 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosGeneric ML PUA (PUA)
GDataWin32.Trojan.PSE.12FI8JT
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Graftor.DD8FAA
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Variant.Graftor.888746
MAXmalware (ai score=82)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazqL+ySmi0j9mvRkOEfa34lE)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Graftor.888746 (B)?

Graftor.888746 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment