Trojan

What is “Trojan:Win32/Phonzy.A!ml”?

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: 1098F1CE48B5D89EE14B.mlw
path: /opt/CAPEv2/storage/binaries/fee792119f7b6fa20797fed82618204a42745eabf480eef20ed9af699faf1169
crc32: 00257938
md5: 1098f1ce48b5d89ee14b1d256531d4f1
sha1: 1ec6940bde7b85ef336a4af5abc5375908d0def8
sha256: fee792119f7b6fa20797fed82618204a42745eabf480eef20ed9af699faf1169
sha512: 0c77aeb818245c03d0a8cf54b2e2c1c14e3440f3c4774926bc2272931f0d6af71036af039d06da265abb91eeda8542b5c23071bc4e7f05523cdd0a41fa8e5b70
ssdeep: 6144:qfKRwAwAaequcDMuYTuM8bPBhukn7HMeEW3atAObhPQv:qfKRwAwjtuwMuYTuHbPB0kmF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T140643A10B640E076F5A302332AEDDADA85AC7C314BD908D7B3844EBADA793E09735757
sha3_384: 6d83197db11e8858c17e2c90ceebc1e382e27d2f774f948551a550b44034a7bbc932fa8b8c4db95c059f4ca4512c9165
ep_bytes: e80d0b0000e974feffff8b4df464890d
timestamp: 2023-11-09 21:30:47

Version Info:

FileVersion: 2.0.0.1
LegalCopyright: 2022-2023 All rights reserved
Translation: 0x0409 0x04b0

Trojan:Win32/Phonzy.A!ml also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.388986
SkyhighGenericRXWM-CV!1098F1CE48B5
ALYacGen:Variant.Lazy.388986
ZillyaTrojan.Agent.Win32.3774189
K7AntiVirusTrojan ( 005adb6a1 )
AlibabaTrojan:Win32/Generic.c448a3c5
K7GWTrojan ( 005adb6a1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.AFZQ
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.388986
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Agent.kbf
F-SecureHeuristic.HEUR/AGEN.1305900
VIPREGen:Variant.Lazy.388986
EmsisoftGen:Variant.Lazy.388986 (B)
IkarusTrojan.SuspectCRC
JiangminTrojan.Generic.hrvzt
VaristW32/S-0960b900!Eldorado
AviraHEUR/AGEN.1305900
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Phonzy.A!ml
ArcabitTrojan.Lazy.D5EF7A
ZoneAlarmUDS:Trojan.Win32.Generic
GDataGen:Variant.Lazy.388986
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R622035
McAfeeGenericRXWM-CV!1098F1CE48B5
VBA32Trojan.Phonzy
MalwarebytesMalware.AI.27822123
PandaTrj/Genetic.gen
RisingTrojan.Agent!8.B1E (TFE:1:dzXmzaXH7GT)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.ADKJ!tr
BitDefenderThetaGen:NN.ZexaF.36680.sy0@aqpWsFgi
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment