Malware

Strictor.273362 (file analysis)

Malware Removal

The Strictor.273362 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.273362 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Strictor.273362?


File Info:

name: 263B2B15FB1AAF9166D3.mlw
path: /opt/CAPEv2/storage/binaries/fdb218eaf21ec87d25d3d95329dec5f202685e24abb0e977fa590579b5c38617
crc32: 3096C1E3
md5: 263b2b15fb1aaf9166d3a6d81a8b79aa
sha1: c8a8f1fd5dff59531d747a157d7814594e15c478
sha256: fdb218eaf21ec87d25d3d95329dec5f202685e24abb0e977fa590579b5c38617
sha512: ae7a41ac864050af70b180d83013edade92025c7a6691c4611135e57e33442aa12496c0561e1189ef2fa02af8bc6748301f8ae0afa8dce21a33b3e2ec22e0874
ssdeep: 49152:dxzUkakaN65+nArwMXrhFrtZM1WppYy6XIGDISngjlnXA3V5DU:dxPakN5+nArdXrhFM1vlyVOVpU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131F57CE23A0BD2DFE1670E74B423F903817C77E24E149921EE6874798AD3D662385778
sha3_384: a59c9a157d1a0d2f301c465bf1d621c6f695db49fd41c1d5d3d159d4921c45b3f7889cf63d9acc2f03f1f88e7a5c9120
ep_bytes: 55e94478fcff5de90f40ffff6195a23f
timestamp: 2012-11-16 22:57:03

Version Info:

CompanyName: Google LLC
FileDescription: Google Installer
FileVersion: 1.3.34.11
InternalName: Google Update
LegalCopyright: Copyright 2018 Google LLC
OriginalFilename: GoogleUpdate.exe
ProductName: Google Update
ProductVersion: 1.3.34.11
Translation: 0x0400 0x04b0

Strictor.273362 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Strictor.273362
FireEyeGeneric.mg.263b2b15fb1aaf91
ALYacGen:Variant.Strictor.273362
CylanceUnsafe
VIPREGen:Variant.Strictor.273362
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.5fb1aa
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Razy-9882105-0
KasperskyUDS:Trojan.BAT.Runner.ct
BitDefenderGen:Variant.Strictor.273362
Ad-AwareGen:Variant.Strictor.273362
SophosTroj/Agent-BHEX
TrendMicroTROJ_GEN.R007C0RIA22
McAfee-GW-EditionBehavesLike.Win32.BadFile.wh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.273362 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Strictor.273362
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=81)
ArcabitTrojan.Strictor.D42BD2
ZoneAlarmUDS:Trojan.BAT.Runner.ct
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366812
McAfeeArtemis!263B2B15FB1A
MalwarebytesTrojan.MalPack.Themida
TrendMicro-HouseCallTROJ_GEN.R007C0RIA22
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.D694!tr
BitDefenderThetaAI:Packer.F9F6FE641F
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Strictor.273362?

Strictor.273362 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment