Trojan

What is “TrojanDownloader:Win32/Delf.LZZ”?

Malware Removal

The TrojanDownloader:Win32/Delf.LZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Delf.LZZ virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Delf.LZZ?


File Info:

name: 13984A5105F5CD0F216D.mlw
path: /opt/CAPEv2/storage/binaries/1a67f9e96297c3491caf5687ddddedd424a78ab52f8d94c079a9747c3ea3e9d1
crc32: 76775365
md5: 13984a5105f5cd0f216dfa8384710a78
sha1: 5d7c4a0e90ce86ad65d47ab5537a4ad70f766382
sha256: 1a67f9e96297c3491caf5687ddddedd424a78ab52f8d94c079a9747c3ea3e9d1
sha512: af54a4ee52e6376b9501bcefd39a126a8b5817e101bc1c208ad62ace53c68852b0c52762158680339132813f447eebe24a7e96fd57de149fbf9bfe4b588c0c6f
ssdeep: 6144:TBKHYmz6mq2pmHmFV2YjnWuwqzeRhvaw4T:04m5bpnL2KnEqCRhvaT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F54233B6AD74CE1D78D0A3921604D1D833E5D4CB504C79722237DAE5AB0F6E95092BE
sha3_384: c3acd67d8305fdd54d314e5f9adde61f478c4cf8c78ccbb7bdbfa1a1818e2d57d21c2f6957ea29d0885056b5bf481ab7
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2011-01-25 07:31:10

Version Info:

CompanyName:
FileDescription: 281600
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

TrojanDownloader:Win32/Delf.LZZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.lQdB
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.262536
FireEyeGeneric.mg.13984a5105f5cd0f
CAT-QuickHealTrojanDownloader.Delf.NK12
SkyhighBehavesLike.Win32.GenDownloader.dc
ALYacGen:Variant.Ursu.262536
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ursu.262536
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( f1000a011 )
BitDefenderGen:Variant.Ursu.262536
K7GWTrojan ( f1000a011 )
Cybereasonmalicious.e90ce8
BitDefenderThetaGen:NN.ZelphiF.36792.rW1baWd4Kddj
VirITTrojan.Win32.Cryptic.CBE
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Delf.QEW
APEXMalicious
ClamAVWin.Packed.Delf-9786618-0
KasperskyTrojan-Downloader.Win32.Delf.aznp
AlibabaTrojanDownloader:Win32/GenDownloader.78578e50
NANO-AntivirusTrojan.Win32.Delf.crlibp
ViRobotTrojan.Win32.A.Downloader.276472.A
TencentTrojan.Win32.Downloader.tgv
SophosMal/DelpDwnld-B
BaiduWin32.Trojan-Downloader.Agent.af
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoader4.5793
ZillyaDownloader.Delf.Win32.18627
TrendMicroTROJ_DLOADR.SMAI
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.262536 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.262536
JiangminTrojanDownloader.Delf.aaad
WebrootW32.Delf.Gen
GoogleDetected
AviraTR/Dldr.Delphi.Gen
VaristW32/Delf.AI.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Delf
KingsoftWin32.Troj.Undef.a
XcitiumTrojWare.Win32.Downloader.Fraudload.AA@2vwxs7
ArcabitTrojan.Ursu.D40188
SUPERAntiSpywareTrojan.Agent/Gen-Delf
ZoneAlarmTrojan-Downloader.Win32.Delf.aznp
MicrosoftTrojanDownloader:Win32/Delf.LZZ
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Delf.R3483
VBA32TrojanDownloader.Delf
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DLOADR.SMAI
RisingTrojan.DL.Win32.Undef.sua (CLOUD)
YandexTrojan.GenAsa!dETtiKvSjKU
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Delf.AZNP
FortinetW32/Delf.QEW!tr.dldr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Delf.LZZ?

TrojanDownloader:Win32/Delf.LZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment