Malware

What is “Graftor.976089”?

Malware Removal

The Graftor.976089 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Graftor.976089 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Uzbek (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.2ip.ua
dgos.top
astdg.top
sergeevih43.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Graftor.976089?


File Info:

crc32: 0BED78D8
md5: d336d82899a7cada20b170c74e3fa0eb
name: D336D82899A7CADA20B170C74E3FA0EB.mlw
sha1: 404aaf84adc38f6067f825653392b6b7b38c4a04
sha256: ff9e059a789e94573fb32a918657d5c5c59b5395fab873cbcec7b1543435fe93
sha512: 8a57d9bfd98ee08d1cf9685a59131dbd98fc3949f54fdc6422b1b8ec382d31f6559610381e9377e9dc02d6db9fd755ee9a6473c3b490c1faecb2c60c0041fbe8
ssdeep: 24576:hIn84fUTEMJ0WbHf1VARKPXrBFGuWB8/CfX6:T/7J0WzfbXrBFd9C/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020a 0x0547

Graftor.976089 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.4adc38
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
BitDefenderGen:Variant.Graftor.976089
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34790.YuW@a4zCCfmG
McAfee-GW-EditionBehavesLike.Win32.Lockbit.cc
FireEyeGeneric.mg.d336d82899a7cada
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_94%
MicrosoftTrojan:Win32/Glupteba!ml
Acronissuspicious
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesTrojan.MalPack
RisingTrojan.Kryptik!1.D7E8 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
Qihoo-360HEUR/QVM10.1.7C97.Malware.Gen

How to remove Graftor.976089?

Graftor.976089 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment