Malware

Lazy.439767 (file analysis)

Malware Removal

The Lazy.439767 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.439767 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.439767?


File Info:

name: D380CBA970A69F808211.mlw
path: /opt/CAPEv2/storage/binaries/d13d7c06f54f96a6c01d719946e3976fb17434fee4af714253856290667a7c89
crc32: CF34F566
md5: d380cba970a69f808211e0e9aafff31d
sha1: fd973a73645c3717fe4656db2739330a6b692ef7
sha256: d13d7c06f54f96a6c01d719946e3976fb17434fee4af714253856290667a7c89
sha512: e153fd6683b6502d3bcbe2e6abfe3e51045e7f44edd4e602336ce21e2e1fc66ee6d53ad6895b3b93a03e248805862a40adb3e047813063d893f1736cee44997f
ssdeep: 12288:rlZIsOJkOHU/hx01/NRPVQ5zCD4VZRDGWF1m3aYhOA6eXVg:vNO2CUOvPVQ5zY431CaYAeXVg
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13DD4AD99FC4F0EA3DDEB787325F2644292C6EA3B0F6E00CED96700653C309A4B5E54A5
sha3_384: 3e310e23dfe68da66e4b3ff26a1f22edcf0deee8b9748a4f148a96a0870f61b91770dd97dfbd733d118cda9084d087f7
ep_bytes: 7c8313de2cea9759290b9ec83b49f672
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Lazy.439767 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.439767
SkyhighBehavesLike.Win32.RAHack.jc
McAfeeTrojan-FVOQ!D380CBA970A6
Cylanceunsafe
VIPREGen:Variant.Lazy.439767
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Lazy.D6B5D7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9828382-0
KasperskyTrojan.Win32.Copak.bthxf
BitDefenderGen:Variant.Lazy.439767
NANO-AntivirusTrojan.Win32.Kryptik.fgfykk
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Copak.hl
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen26.15400
ZillyaTrojan.Kryptik.Win32.4495426
TrendMicroTROJ_GEN.R03BC0DBG24
FireEyeGeneric.mg.d380cba970a69f80
EmsisoftApplication.Generic (A)
IkarusTrojan.Win32.Glupteba
JiangminTrojan.Generic.cldgs
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.bthxf
GDataWin32.Trojan.PSE.SNMJGU
GoogleDetected
AhnLab-V3Packed/Win.FJB.R632556
Acronissuspicious
VBA32Trojan.Khalesi
ALYacGen:Variant.Lazy.439767
MAXmalware (ai score=89)
MalwarebytesCrypt.Trojan.MSIL.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DBG24
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
BitDefenderThetaGen:NN.ZexaF.36744.M4Z@aiCqpIk
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.3645c3
DeepInstinctMALICIOUS

How to remove Lazy.439767?

Lazy.439767 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment