Malware

Lazy.58561 (file analysis)

Malware Removal

The Lazy.58561 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.58561 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Lazy.58561?


File Info:

name: FE5A6B78586DD2710A0E.mlw
path: /opt/CAPEv2/storage/binaries/19f5b04676241f93c3d3be310229435cfb86007c4f68c430580f2957aa07f593
crc32: EFE60A05
md5: fe5a6b78586dd2710a0ea0e12ed83495
sha1: 18b9bfcde14801f9a80d3b1d4188419987964bb0
sha256: 19f5b04676241f93c3d3be310229435cfb86007c4f68c430580f2957aa07f593
sha512: a88b65e8a14914de05838c633f75d03b99bbd8894896f4779e1f0f8443f28de4e39b46e62c9137b2e8b4f6fdc41104109a24d337e558909b5bfed194aab1d964
ssdeep: 3072:CIbh1oVvW4kUrBaFjB/x34USjE67M2md3YgBAghuv4ONFjtX8Y:pbGrBUB/+rmdMNF18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC145A22A89F4CA7C7D41570AF6DC17A2228ED7D1C21492BB6DF7E2F7A7D00B1047229
sha3_384: eaccabc463e856226676b1c15c29c001b082870b14992a291daa375cc69ae774756091476c0075291b8aaf5194ea7789
ep_bytes: ff250020400000000000000000000000
timestamp: 2050-03-21 10:32:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Microsoft
FileDescription: WindowsFormsApp22
FileVersion: 1.0.0.0
InternalName: WindowsFormsApp22.exe
LegalCopyright: Copyright © Microsoft 2021
LegalTrademarks:
OriginalFilename: WindowsFormsApp22.exe
ProductName: WindowsFormsApp22
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.58561 also known as:

LionicTrojan.MSIL.Dapato.b!c
MicroWorld-eScanGen:Variant.Lazy.58561
FireEyeGeneric.mg.fe5a6b78586dd271
McAfeeArtemis!FE5A6B78586D
K7AntiVirusTrojan-Downloader ( 0058b9071 )
AlibabaTrojanDropper:MSIL/Dapato.d911ea83
K7GWTrojan-Downloader ( 0058b9071 )
Cybereasonmalicious.8586dd
CyrenW32/Trojan.WMRM-3239
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/TrojanDownloader.Agent.JSC
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Dropper.MSIL.Dapato.gen
BitDefenderGen:Variant.Lazy.58561
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan-dropper.Dapato.Efks
Ad-AwareGen:Variant.Lazy.58561
EmsisoftGen:Variant.Lazy.58561 (B)
ZillyaDropper.Dapato.Win32.82299
TrendMicroTROJ_GEN.R002C0WKU21
McAfee-GW-EditionArtemis
SophosMal/Generic-S
IkarusTrojan.Dropper
GDataGen:Variant.Lazy.58561
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=81)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34084.mm0@a4aZKyj
ALYacGen:Variant.Lazy.58561
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PowerShell
TrendMicro-HouseCallTROJ_GEN.R002C0WKU21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Lazy.58561?

Lazy.58561 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment