Malware

Heur.BZC.PZQ.Boxter.591.3087B31D (file analysis)

Malware Removal

The Heur.BZC.PZQ.Boxter.591.3087B31D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.BZC.PZQ.Boxter.591.3087B31D virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Heur.BZC.PZQ.Boxter.591.3087B31D?


File Info:

name: D6A6925C19092E51F63E.mlw
path: /opt/CAPEv2/storage/binaries/62723352e71e73d844c0b3493cc26a88daab6c97f52bf41910f7155e6c653e00
crc32: EBFBACA4
md5: d6a6925c19092e51f63eb2a8914b0973
sha1: 0f26a44ba82c3df3a9235f2be95ff08fff2d0081
sha256: 62723352e71e73d844c0b3493cc26a88daab6c97f52bf41910f7155e6c653e00
sha512: caa30132aae3e7bba0103d189b28c9746c3fa3a23f3273b9579a765175a29b2360757810dbf8ffd0fcb64db4d22a0fd3678b1d53f5808348df615013e1deb9ae
ssdeep: 3072:t2sMWkzbJh1qZ9QW69hd1MMdxPe9N9uA0hu9TBfcXZSsYvmoxs2PM:UbJhs7QW69hd1MMdxPe9N9uA0hu9TBI7
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1FF144A23B6A01089D6B582B5C5762745E7B23C751721A3CB2BB473B61B3B8C68F3D391
sha3_384: a7b43f7734291f2bbb93a2162da721b1b7e47d207951b10d352d5bf28de83697237a31e2694473f1395874adf491774e
ep_bytes: 4883ec2849c7c0600100004831d248b9
timestamp: 2018-02-01 19:43:24

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
ProductName: DiscordTokenGen
OriginalFilename: TokenGenDiscord
InternalName: SpamBotDiscordTokenGen
FileDescription: This program generate available discord tokens to raid discord servers
LegalCopyright: num
Comments: none
Translation: 0x0000 0x04e4

Heur.BZC.PZQ.Boxter.591.3087B31D also known as:

LionicTrojan.PowerShell.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanHeur.BZC.PZQ.Boxter.591.3087B31D
FireEyeGeneric.mg.d6a6925c19092e51
McAfeeArtemis!D6A6925C1909
CylanceUnsafe
BitDefenderHeur.BZC.PZQ.Boxter.591.3087B31D
K7GWTrojan ( 0052796d1 )
K7AntiVirusTrojan ( 0052796d1 )
CyrenW64/Kryptik.FDL.gen!Eldorado
SymantecDownloader
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Downloader.Win32.PsDownload
AlibabaBackdoor:Win32/Kryptik.a06078b8
Ad-AwareHeur.BZC.PZQ.Boxter.591.3087B31D
EmsisoftHeur.BZC.PZQ.Boxter.591.3087B31D (B)
TrendMicroTROJ_GEN.R002C0WLB21
McAfee-GW-EditionBehavesLike.Win64.Generic.ch
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraTR/B2E.Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataHeur.BZC.PZQ.Boxter.591.3087B31D
CynetMalicious (score: 100)
VBA32Backdoor.PowerShell
ALYacHeur.BZC.PZQ.Boxter.591.3087B31D
MAXmalware (ai score=83)
TrendMicro-HouseCallTROJ_GEN.R002C0WLB21
TencentWin32.Backdoor.Agent.Wsju
IkarusTrojan.PowerShell.Crypt
FortinetPowerShell/Kryptik.H!tr
AVGWin64:Trojan-gen
Cybereasonmalicious.c19092
AvastWin64:Trojan-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Heur.BZC.PZQ.Boxter.591.3087B31D?

Heur.BZC.PZQ.Boxter.591.3087B31D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment