Spy Trojan

What is “Trojan-Spy.Win32.Zbot.aygc”?

Malware Removal

The Trojan-Spy.Win32.Zbot.aygc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.aygc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:24001, :0
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Clears web history

How to determine Trojan-Spy.Win32.Zbot.aygc?


File Info:

name: E539653E9B9B586A70F1.mlw
path: /opt/CAPEv2/storage/binaries/0c760d9df3fb6eb7acf741ea4f87befc675ae8bb847ded496560dc4a7fd8b29d
crc32: BD74C4B9
md5: e539653e9b9b586a70f174204dbccb5d
sha1: 56f42aeb11faab42fa8e27f330178e5d01518a42
sha256: 0c760d9df3fb6eb7acf741ea4f87befc675ae8bb847ded496560dc4a7fd8b29d
sha512: da502a024db6c6ac31e5e2dce8b88715be10e67fceefa5390dddd8c30e74d47ce1d0286e3353ca60492509c32bbc8b974fbe9541831e30ab73a5a1c489bd880f
ssdeep: 3072:AiU6RceqvlxY3CNZj3OTft7a7dBLDDvb6b00gqCUIqlsLWd1ZM5:bpceqtxY3CvjrBLnbEBgjfnLOM5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15724D00B91898F76D2F52736FC8A7E63FB6D716156E6878B07914E027EF362E2103061
sha3_384: 23427cd71a055cf376a40bf3d112207b45a720ad7a6fa76bdd6050503405eb8d4d376d1a987c45325d7a2b9e2cc744f1
ep_bytes: 558bec83c4e4ff75e451e855fbfeffc9
timestamp: 2006-02-02 14:57:18

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.aygc also known as:

BkavW32.MosquitoQKB.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e539653e9b9b586a
McAfeePWS-Zbot.aa
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/Kryptik.47626d9b
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e9b9b5
VirITBackdoor.Win32.Qbot.DD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.JSA
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.aygc
BitDefenderGen:Heur.Mint.Dreidel.nmW@xmFj5Vic
NANO-AntivirusTrojan.Win32.Zbot.iksll
ViRobotTrojan.Win32.A.Zbot.220160.P
MicroWorld-eScanGen:Heur.Mint.Dreidel.nmW@xmFj5Vic
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Zbot.Aiht
Ad-AwareGen:Heur.Mint.Dreidel.nmW@xmFj5Vic
EmsisoftGen:Heur.Mint.Dreidel.nmW@xmFj5Vic (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebBackDoor.Qbot.81
ZillyaTrojan.Zbot.Win32.38323
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosMal/Generic-R + Mal/Zbot-AV
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Dreidel.nmW@xmFj5Vic
JiangminTrojanSpy.Zbot.ausq
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Troj.Zbot.(kcloud)
ArcabitTrojan.Mint.Dreidel.E5D166
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
ZoneAlarmTrojan-Spy.Win32.Zbot.aygc
MicrosoftPWS:Win32/Zbot!ZA
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
BitDefenderThetaAI:Packer.43C938CD1F
ALYacGen:Heur.Mint.Dreidel.nmW@xmFj5Vic
TACHYONTrojan-Spy/W32.ZBot.220160.Z
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!RZIJsgUnId8
IkarusTrojan.Win32.Spyeye
MaxSecureTrojan.Malware.2892799.susgen
FortinetW32/Zbot.AYGC!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.Win32.Zbot.aygc?

Trojan-Spy.Win32.Zbot.aygc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment