Malware

Should I remove “Ser.Lazy.6132”?

Malware Removal

The Ser.Lazy.6132 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Lazy.6132 virus can do?

  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • A script or command line contains a long continuous string indicative of obfuscation

How to determine Ser.Lazy.6132?


File Info:

name: 2507CB051DBD215191CE.mlw
path: /opt/CAPEv2/storage/binaries/2ea419aa77faa13e0c484e0adcf0ff2fccbeb5372ae466066ff4a5a975accd97
crc32: 4BE6093D
md5: 2507cb051dbd215191cef52e51bd01f8
sha1: 0ecf26c1c922da2d41954f6e5e6756aafdbb1427
sha256: 2ea419aa77faa13e0c484e0adcf0ff2fccbeb5372ae466066ff4a5a975accd97
sha512: dd9331e73e0c82e1652e0d7ec2537ec62114b7c531aa3e99376f9083507221c5d3478b7b2256735ef81c6bca92527a73f7e9530769fafd06695d6161a961dd65
ssdeep: 6144:a2A3/Y0xi1h0oPEpxpQDpOYaQ3aH7ruNmGdn63:aNw0xiz0oPEXpCLSruNmOS
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1EA848E01F4D08431D93A34321974E7BA4AADB5701A596BDF5BEC08BBAF306C1DB16A1F
sha3_384: 4d603be57b4bd9a2e24b9d06683bc018153a40883a2fe58a6c600b5542fa5a0c864381f9bb2b563c0a8b79e353d7b98b
ep_bytes: 558bec837d0c017505e8d0030000ff75
timestamp: 2024-03-08 00:33:18

Version Info:

0: [No Data]

Ser.Lazy.6132 also known as:

LionicTrojan.Win32.Generic.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Lazy.6132
FireEyeGen:Variant.Ser.Lazy.6132
SkyhighBehavesLike.Win32.Generic.fh
McAfeeArtemis!2507CB051DBD
SangforDropper.Win32.Lazy.Vla5
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanDownloader:Script/DropperX.fd24f524
BitDefenderThetaGen:NN.ZedlaF.36802.xu4@aaqducci
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SXY
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Script.Generic
BitDefenderGen:Variant.Ser.Lazy.6132
AvastWin32:DropperX-gen [Drp]
SophosMal/Generic-S
VIPREGen:Variant.Ser.Lazy.6132
EmsisoftGen:Variant.Ser.Lazy.6132 (B)
GoogleDetected
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Ser.Lazy.D17F4
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataGen:Variant.Ser.Lazy.6132
AhnLab-V3Dropper/Win.Generic.C5597352
ALYacGen:Variant.Ser.Lazy.6132
MAXmalware (ai score=87)
Cylanceunsafe
RisingTrojan.Generic@AI.99 (RDML:YX4yRGqUyXkY0Xubdfuc8Q)
IkarusTrojan-Dropper.Win32.Agent
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Ser.Lazy

How to remove Ser.Lazy.6132?

Ser.Lazy.6132 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment