Malware

Lazy.502565 information

Malware Removal

The Lazy.502565 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.502565 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.502565?


File Info:

name: C33D43F37E362C82FBD3.mlw
path: /opt/CAPEv2/storage/binaries/343911b29afcec9360071882ec8a447cd729c142e88823632739b58c6756aa73
crc32: 60353AD4
md5: c33d43f37e362c82fbd3ef05c8c9e5f2
sha1: 605b1340266f3a810de40d07237156d55940f8b7
sha256: 343911b29afcec9360071882ec8a447cd729c142e88823632739b58c6756aa73
sha512: e5d865bfa38ae0e1c6d8fc338df1acabb6632ca32ae0d8b0952d194527c9506e68d6534a62b86d41f67ea9027482d5b3da06b4d0461aca7e88a9b54e5877347a
ssdeep: 768:7QN8Fmy2AcYNZ192P2F4bpu9fWWq53EEP1oC4jtO72u:7QN8VxzBTybpu9fWWq53XoCT72u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C03A3786FC559B6E377C2B6C9F2D6C6A436BD6778169D0C60CA33014833B43A8A1D1E
sha3_384: 9d0c50595c192214bf57c183b9f07cdb8c751623d6da91da6fd82954a4a6cab82339d5b1201708894d6365004c19bb42
ep_bytes: 60be008050008dbe0090ffff57eb0b90
timestamp: 2013-10-29 08:38:25

Version Info:

0: [No Data]

Lazy.502565 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.1e!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.502565
FireEyeGeneric.mg.c33d43f37e362c82
SkyhighBehavesLike.Win32.PWSZbot.nm
McAfeeArtemis!C33D43F37E36
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.226715
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.3182350c
BaiduWin32.Trojan-Downloader.Small.ck
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BNSZ
APEXMalicious
ClamAVWin.Downloader.Zbot-10025749-0
KasperskyTrojan-Spy.Win32.Zbot.qnlf
BitDefenderGen:Variant.Lazy.502565
AvastWin32:Downloader-UNP [Drp]
TencentTrojan-Downloader.Win32.Waski.16000151
SophosMal/Generic-S
F-SecureTrojan.TR/Yarwi.B.20
DrWebTrojan.Siggen6.18385
VIPREGen:Variant.Lazy.502565
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Lazy.502565 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fucp
GoogleDetected
AviraTR/Yarwi.B.20
VaristW32/Upatre.RG.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.b.997
MicrosoftTrojan:Win32/Phonzy.A!ml
XcitiumTrojWare.Win32.Injector.KXE@5415yx
ArcabitTrojan.Lazy.D7AB25
ZoneAlarmTrojan-Spy.Win32.Zbot.qnlf
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gandcrab.C3050690
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.cmIfam2yFAfi
ALYacGen:Variant.Lazy.502565
MAXmalware (ai score=80)
VBA32Malware-Cryptor.3113
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!Vbl1wqBDwro
IkarusTrojan.Win32.Badur
MaxSecureTrojan.Upatre.Gen
FortinetW32/Zbot.QNLF!tr
AVGWin32:Downloader-UNP [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Zbot.DI!MTB

How to remove Lazy.502565?

Lazy.502565 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment