Trojan

Trojan:Win32/Phonzy.A!ml malicious file

Malware Removal

The Trojan:Win32/Phonzy.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.A!ml virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Phonzy.A!ml?


File Info:

name: C6704299606668C7210A.mlw
path: /opt/CAPEv2/storage/binaries/21650127b5dfb99b920123397cab231602418c9e1337603b57dcc9b3b19fcb2c
crc32: CAAEC284
md5: c6704299606668c7210a85a5daa1a09b
sha1: 1a5a017dae8d27832cfe0ccc0166072c4be773eb
sha256: 21650127b5dfb99b920123397cab231602418c9e1337603b57dcc9b3b19fcb2c
sha512: 0ce597db5fe17da49d1e90b59eca1bf83bf98a66d83bf530b1d15e11db14ac6ecc257b3044c9128194cf578aa9c2aee6211c827fe58006a2c7da8da27a674351
ssdeep: 6144:UC0tHnFRp+tNThxOA0K1LF+uuyG5WO2lqRdwx/:Q7MThxOKF8uuyG5WO2lqI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEC471137620C821F4161238D26687FDBAF56F589D62038BB690BDB63C7E5736EDE108
sha3_384: 4cd2041dc24143ad2650dd4dc47f94508fd0083bd65075cc19dbb59ae069e1432aa61d8a0f86225ef71eeda327d1bf98
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 2000-05-19 10:11:55

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.A!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
SkyhighBehavesLike.Win32.Generic.hm
MalwarebytesTrojan.Agent
SangforDropper.Win32.FlyStudio.Vsc2
AlibabaTrojanDropper:Win32/Generic.a1ab9555
Cybereasonmalicious.dae8d2
VirITTrojan.Win32.Generic.BIHI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b2d6b4
F-SecureTrojan.TR/Dropper.Gen
SophosGeneric ML PUA (PUA)
IkarusRiskware.Win32.FlyStudio
GDataWin32.Riskware.FlyStudio.C
JiangminRiskTool.FlyStudio.wf
Webroot
VaristW32/FlyAgent.J.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Wacatac.b
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
MicrosoftTrojan:Win32/Phonzy.A!ml
GoogleDetected
McAfeeArtemis!C67042996066
TACHYONTrojan/W32.Agent.548352.M
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CIP23
RisingDropper.Generic!8.35E (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Trojan:Win32/Phonzy.A!ml?

Trojan:Win32/Phonzy.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment