Malware

Lazy.230799 malicious file

Malware Removal

The Lazy.230799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.230799 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Lazy.230799?


File Info:

name: 11F7F7EBEB716E3AA81F.mlw
path: /opt/CAPEv2/storage/binaries/42629a9e64750e028662193c1d0e85fd40626f692380ffd6bcf196eaf94e6bb2
crc32: D83D6F8D
md5: 11f7f7ebeb716e3aa81fd0ce7ac480c5
sha1: 93fef88b23892f17bec14670265712226cac54fd
sha256: 42629a9e64750e028662193c1d0e85fd40626f692380ffd6bcf196eaf94e6bb2
sha512: 805cc05dca11ed818f6dcc7248b3caadf6a7ef5efa708600272b12bcffd7685ade2a6c4a4aef9fa4908f51e3a427cb684393b9417e0a8fb0f5fad23028b222e9
ssdeep: 6144:/aMS9It7qyhU1nM7XaT9/GBQBLOWNAOnycWJ4BbPxf8ipTOfB:/aMS2t7qyhU1MAYTSBbB8HB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17D74BF82F6A2C4F1C86118B51DE4DBB15E3B7D214B20C9D7A7A40B7E8E707C1F97582A
sha3_384: a2178d2cc2c440654c0bcfe4df78052d2fceb67a6940aeb6118cec8a386675b8fe116d390d3e5f9bb33008a10143d5e2
ep_bytes: e8b1050000e974feffff558bec8b4508
timestamp: 2022-08-04 23:05:50

Version Info:

0: [No Data]

Lazy.230799 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.230799
ClamAVWin.Keylogger.Fugrafa-9961659-0
FireEyeGeneric.mg.11f7f7ebeb716e3a
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPREGen:Variant.Lazy.230799
K7AntiVirusTrojan ( 00596a121 )
AlibabaTrojanSpy:Win32/Stealer.91a02bff
K7GWTrojan ( 00596a121 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/S-3cb8c202!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HQJN
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.230799
NANO-AntivirusTrojan.Win32.Stealer.jrcuby
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Variant.Lazy.230799
EmsisoftGen:Variant.Lazy.230799 (B)
DrWebTrojan.PWS.Siggen3.20777
ZillyaTrojan.Kryptik.Win32.3862764
TrendMicroTrojanSpy.Win32.REDLINE.YXCHEZ
McAfee-GW-EditionRDN/Generic PWS.y
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataWin32.Trojan.PSE.1SOG6RN
JiangminTrojanSpy.Stealer.aaof
AviraTR/Kryptik.ujjcw
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASCommon.2AC
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R509444
ALYacGen:Variant.Lazy.230799
MalwarebytesSpyware.Stealer
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCHEZ
RisingTrojan.Generic@AI.100 (RDML:U85BSdBC96aPd0JEjqfzqg)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaE.34592.wqY@aCrTPPc
AVGWin32:PWSX-gen [Trj]

How to remove Lazy.230799?

Lazy.230799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment