Malware

How to remove “Strictor.272448”?

Malware Removal

The Strictor.272448 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.272448 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Strictor.272448?


File Info:

name: 187353C69FBE486D2CFD.mlw
path: /opt/CAPEv2/storage/binaries/6970f9104681d057013a0581c81451b7afe1a60f64caac2c9c72438fbf26544d
crc32: FBF5E323
md5: 187353c69fbe486d2cfd4c8c7b088949
sha1: f71d45cf49aab535189a8cf9def8e64f7ffb61b1
sha256: 6970f9104681d057013a0581c81451b7afe1a60f64caac2c9c72438fbf26544d
sha512: 55e59a7734414fdf413fdb53b798cf09c28160e67dfd0a057b1f27a2accb8034a7a31beac2a243d26600fabd3b2176f73a32fb37ee720de2d03ced7ce777d7bc
ssdeep: 12288:uVZvnNVvw7NQ00SX7NzV4SOXR80gP3xyvSiB4x+7i12gqtwB+J24ASn:uV1NVvwq87NNN3xiSir7iF4bD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D35BE8280830E65C8241F74A1292D358AABAFFF7E75A0D55DDEF93A33B71E24134935
sha3_384: 3ab787f7f0d74c0e193d455e6cd45b8918abbc3f50ecc90cc6d143328c027998509881089e4b32b646c7c3233282b66a
ep_bytes: eb02677e50eb02e810e81a000000eb04
timestamp: 2050-11-20 02:50:12

Version Info:

CompanyName: Samsung Electronics
FileDescription: Samsung Portable SSD Software
FileVersion: 1.6.7.50
InternalName: SamsungPortableSSD.exe
LegalCopyright: Copyright (C) 2018 Samsung Electronics
OriginalFilename: SamsungPortableSSD.exe
ProductName: Samsung Portable SSD Software
ProductVersion: 1.6.7.50
Translation: 0x0400 0x04b0

Strictor.272448 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.272448
FireEyeGeneric.mg.187353c69fbe486d
ALYacGen:Variant.Strictor.272448
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058da0a1 )
K7GWTrojan ( 0058da0a1 )
Cybereasonmalicious.f49aab
CyrenW32/Obsidium.A.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.Obsidium.IY
APEXMalicious
ClamAVWin.Packed.Obsidium-9950064-0
KasperskyTrojan-Spy.Win32.Stealer.brad
BitDefenderGen:Variant.Strictor.272448
AvastWin32:DangerousSig [Trj]
Ad-AwareGen:Variant.Strictor.272448
EmsisoftGen:Variant.Strictor.272448 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Strictor.272448
AviraHEUR/AGEN.1248332
MAXmalware (ai score=81)
ArcabitTrojan.Strictor.D42840
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.RedLine.C5040156
McAfeeArtemis!187353C69FBE
TACHYONTrojan-Spy/W32.InfoStealer.1088899
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack.Obsidium
TrendMicro-HouseCallTROJ_GEN.R067H07ED22
RisingTrojan.Generic@AI.100 (RDML:WqIevffqegvYXP+g0H4TLw)
IkarusTrojan.Win32.Obsidium
MaxSecureTrojan.Malware.151100921.susgen
BitDefenderThetaGen:NN.ZexaF.34712.cr3@aWik2jdi
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Strictor.272448?

Strictor.272448 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment