Malware

What is “Lazy.507273”?

Malware Removal

The Lazy.507273 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.507273 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Lazy.507273?


File Info:

name: E666743A8C373B72FC79.mlw
path: /opt/CAPEv2/storage/binaries/70113c877754d7b362bc2932c2280dbea62e0ad44afbe5e97a1638b98b50cc5e
crc32: C8D4D780
md5: e666743a8c373b72fc79739c9b31e576
sha1: bb3279f96c40ee1c64e7518f9d097a8a433bfab0
sha256: 70113c877754d7b362bc2932c2280dbea62e0ad44afbe5e97a1638b98b50cc5e
sha512: 193a7d0d3276d977c4242fe6d94cce75493270d0cc2e3e53374cf65e5e89d8c3a3de40a50ab8cec6f4a0893bb5fa0f80a56caf836b30d0d87a010bbf1a6626c8
ssdeep: 384:bVCPwFRuFn65arz1ZhdaXFXSCVQTLfjDp6HnSq:bVCPwFRo6CpwXFXSqQXfjAHX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AB26C3076D96851E3B7877060F7C096617EBCA17E264D0D3C8EB39D4EB3B91994220E
sha3_384: 4b2831a3d2f35b75d4c3aea4fc696146ed0a7f002649bdd79d80fc504a14f5d7372d8b9e0cd66b6a335034cd4d98fa45
ep_bytes: 60be008000088dbe0090ffff5783cdff
timestamp: 2012-02-16 02:43:40

Version Info:

0: [No Data]

Lazy.507273 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Lazy.507273
SkyhighBehavesLike.Win32.PWSZbot.mh
McAfeeGeneric-FANY!A6E7B4480B22
Cylanceunsafe
VIPREGen:Variant.Lazy.507273
SangforSuspicious.Win32.Save.a
K7GWTrojan-Downloader ( 000078781 )
K7AntiVirusTrojan-Downloader ( 000078781 )
BaiduWin32.Trojan-Downloader.Small.c
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
ClamAVWin.Trojan.Zbot-64721
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Lazy.507273
NANO-AntivirusTrojan.Win32.DownLoad3.cjdzno
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bfcd69
EmsisoftGen:Variant.Lazy.507273 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen2
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Bublik.Win32.31050
TrendMicroTROJ_UPATRE.SM37
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.e666743a8c373b72
SophosTroj/Agent-AECC
IkarusBackdoor.Win32.Androm
JiangminTrojan/Bublik.gbl
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
VaristW32/Trojan.FQOC-6504
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.b.966
MicrosoftTrojan:Win32/Phonzy.B!ml
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
ArcabitTrojan.Lazy.D7BD89
ViRobotTrojan.Win32.Zbot.25600[UPX]
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.10565N
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3069854
Acronissuspicious
VBA32Trojan.Bublik
ALYacGen:Variant.Lazy.507273
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingMalware.FakePDF/ICON!1.9C28 (CLASSIC)
YandexTrojan.GenAsa!0NHD56KEAmA
MAXmalware (ai score=84)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.AEBW!tr
BitDefenderThetaGen:NN.ZexaF.36804.bmLfai7iNjoi
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Lazy.507273?

Lazy.507273 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment