Trojan

Trojan:Win32/Phonzy.A!ml malicious file

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Uses XCOPY for copying files

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: 20CB1822AA86AADEDE85.mlw
path: /opt/CAPEv2/storage/binaries/cdf111ef3ac75f8fbbee70cb660e70c10671dc6c674a67155e89b8eb23cee964
crc32: 4F0D7AD2
md5: 20cb1822aa86aadede859a9ceedc3413
sha1: 147921316a2aeb62b5ca89b840a4fa54cca06403
sha256: cdf111ef3ac75f8fbbee70cb660e70c10671dc6c674a67155e89b8eb23cee964
sha512: 262facbc6178d69444c9562660ea79633850cf39a94a0d1a686660ab4c23717ae4de6bc82988c48fe8e29186cc3c052c45898e8077048fabae292a16a0d586f0
ssdeep: 768:Zpm7BcEKNvBcvL6VeRNL1a6ZO4PTPz+o+CKr3zQ4NuVVWgP4+zrUnbcuyD7UBZOi:ZpfEKNCj6VoJl9Go5K7s4Nu3Wnouy8Bz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18523F24796C8A9ABF42490389C5F2C586E9CD72876C0C332FDC137765FA1A074B1D216
sha3_384: 85acf373ea8fcc165fbca2ea840f06f0ab2f984fc5b0f9c8afdeea9ac8b5d351d3c175477cf7c37494738af26c87b525
ep_bytes: 60be152041008dbeebeffeff5789e58d
timestamp: 2019-05-16 14:07:17

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.20cb1822aa86aade
CAT-QuickHealPUA.ObfuscatedPMF.S31670779
SkyhighBehavesLike.Win32.Generic.pc
McAfeeArtemis!20CB1822AA86
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.16a2ae
VirITTrojan.Win32.Genus.TMT
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bdaa53
TACHYONTrojan/W32.KillFiles.89600
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
VaristW32/Agent.BJD.gen!Eldorado
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Phonzy.A!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3347471
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CLM23
RisingTrojan.Wacatac!8.10C01 (CLOUD)
IkarusTrojan.Win32
MaxSecureTrojan.Malware.216064600.susgen
FortinetW32/Nitol.AB!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment