Malware

Strictor.274673 (B) malicious file

Malware Removal

The Strictor.274673 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Strictor.274673 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Strictor.274673 (B)?


File Info:

name: 9953EA23E891FE1AEF4C.mlw
path: /opt/CAPEv2/storage/binaries/2b46db3c043de49ee4a10bf5b721712e72c0f8f5a4f77a92241e0fe794860d2e
crc32: EE1271FF
md5: 9953ea23e891fe1aef4c877510a3f4c7
sha1: f9d7fec99fba4484cf8b7f844bb6ce5833ade3fb
sha256: 2b46db3c043de49ee4a10bf5b721712e72c0f8f5a4f77a92241e0fe794860d2e
sha512: dfe7e26a4609d8a6381959b008903daf138fbb80ceb8e6f6911c4914aff97adcd49b67daaa48f431adf9dfff8493a76c0a450b56a1286cd9453e8f2b8074f374
ssdeep: 24576:Pw1gPujKrOz1sJGup7U1gVinQvgOKAMHko+CofjTC88UGeZgVE:PAz1ssnugQ1MHklYUGCYE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B45028059816BD6DD54ED7487C7F2F22A36AD7FDA9D1F3A18D438332B302E496049A4
sha3_384: eee0a36cbe59e27fb3034a2fd5e91c64e3e9014bacea9382c6496af161586a598bcf4a1349ab349bfff187d4b8a77373
ep_bytes: 6801f06200e801000000c3c3498bda39
timestamp: 2022-07-28 20:01:26

Version Info:

CompanyName: 360-360
FileDescription: 苏打办公,一款主打简约、高效的办公平台,它占用内存小,功能齐全简洁。产品理念是让办公成为轻松的事。苏打办公集成PDF阅读、PDF转换、PDF合并拆分、图片识别文字等功能,并拥有优质的模板中心,提供PPT模板、Word模板、Excel模板等服务。
FileVersion: 3.0.2.1212
InternalName: Skype.exe
LegalCopyright: webadinmn
OriginalFilename: Skype.exe
ProductName: 苏打办公
ProductVersion: 3.0.2.1212
SquirrelAwareVersion: 1
Translation: 0x0804 0x04b0
Comments: 一款主打简约、高效的办公平台

Strictor.274673 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.l!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.7717
MicroWorld-eScanGen:Variant.Strictor.274673
FireEyeGen:Variant.Strictor.274673
ALYacGen:Variant.Strictor.274673
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Strictor.274673
SangforTrojan.Win32.Qqware.Vvsn
K7AntiVirusTrojan ( 0059380b1 )
AlibabaTrojan:Win32/QQWare.74d3a55f
K7GWTrojan ( 0059380b1 )
Cybereasonmalicious.99fba4
BitDefenderThetaGen:NN.ZelphiF.36250.jX0aa0egDdfj
CyrenW32/Trojan.IFX.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/QQWare.DM
APEXMalicious
KasperskyVHO:Trojan-Spy.Win32.Convagent.gen
BitDefenderGen:Variant.Strictor.274673
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Agen.Swhl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1336651
ZillyaTrojan.QQWare.Win32.6963
McAfee-GW-EditionBehavesLike.Win32.Obfuscated.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.274673 (B)
GDataGen:Variant.Strictor.274673
GoogleDetected
AviraHEUR/AGEN.1336651
Antiy-AVLTrojan/Win32.QQWare
ArcabitTrojan.Strictor.D430F1
ZoneAlarmVHO:Trojan-Spy.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R508223
McAfeeGenericRXTZ-TG!9953EA23E891
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.QQWare!8.105 (TFE:5:ExAH3N7cgP)
IkarusTrojan.Win32.QQWare
MaxSecureTrojan.Malware.109800502.susgen
FortinetW32/QQWare.DM!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Strictor.274673 (B)?

Strictor.274673 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment