Malware

Should I remove “Lazy.59523”?

Malware Removal

The Lazy.59523 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.59523 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

wpad.local-net
fenixzone.net

How to determine Lazy.59523?


File Info:

name: D6A292CF427F724BA5F4.mlw
path: /opt/CAPEv2/storage/binaries/abff4a8b69d1655294a9b97a406c20239c799bd41ef0dd7a919462eaf800c51d
crc32: 1EBFD987
md5: d6a292cf427f724ba5f48b72a47e2a9a
sha1: a1600adb3211f93b9fe04dd15c9c775c51a78b82
sha256: abff4a8b69d1655294a9b97a406c20239c799bd41ef0dd7a919462eaf800c51d
sha512: cef3575c41effe8750a5f97e2f9113099b5a13302f2a80fc9ffeadec4ae96ba4d792fd9f83071cd62a304d93b30f6597276917ed9003ad0a4dbbd53f314ddf60
ssdeep: 24576:kkrDFxeCKNLeTThbx9RwY62yB1IUYUBsjkbeAvmTKXqsL074by1okXyKbyuGvswY:kkrDFTOQYu9yphLzQW7BBbgLzQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171558D7D6BB88D3FD8BF1734A6E001222270E5966706EF1E401654DC2AD3BE29D163E7
sha3_384: e3d075ba38b31c08f1bb90658853cf55c58292c9f44db09d38bb8b932a69a7dcfb36cd2595c24617ed01ef038609f26f
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-22 21:41:58

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: FenixZone
FileDescription: FenixZoneDownloader
FileVersion: 1.0.0.0
InternalName: FenixZone Downloader.exe
LegalCopyright: Copyright © FenixZone 2017
LegalTrademarks:
OriginalFilename: FenixZone Downloader.exe
ProductName: FenixZoneDownloader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Lazy.59523 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGen:Variant.Lazy.59523
McAfeeArtemis!D6A292CF427F
AlibabaTrojan:MSIL/Generic.7cb6a57c
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderGen:Variant.Lazy.59523
MicroWorld-eScanGen:Variant.Lazy.59523
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Lazy.59523
EmsisoftGen:Variant.Lazy.59523 (B)
McAfee-GW-EditionArtemis
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.59523
AviraTR/Dropper.MSIL.Gen2
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Lazy.DE883
MicrosoftProgram:Win32/Uwamson.A!ml
ALYacGen:Variant.Lazy.59523
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1294031746
TrendMicro-HouseCallTROJ_GEN.R002H09L221
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen

How to remove Lazy.59523?

Lazy.59523 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment