Trojan

Trojan:Win32/Phonzy.B!ml (file analysis)

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 74376C47A96FCF891330.mlw
path: /opt/CAPEv2/storage/binaries/ed63fdc0159629a08a903737e48cfe8fe5b6bdf5bb0fcf177dc488976928c9b9
crc32: 52FCA4B9
md5: 74376c47a96fcf891330bd3c50f3e917
sha1: 60424cdf6e16f05a54719cf3b36f5640b450d968
sha256: ed63fdc0159629a08a903737e48cfe8fe5b6bdf5bb0fcf177dc488976928c9b9
sha512: 9dc28078a0ba35f70a21c87b6b43b6e6096aa6bc89d91e7d2a272e3f0eccde489bd7678ed6b1820e5f9ed0f4a5a993d35f39c484f6d880721738d5469956a6a8
ssdeep: 768:VTU8/1+mFYBQ1qhxu1+n7y/8HaFDPKNCkPLBpUO7J8lx+wB7Pnbjqz9UtkXWmVU9:mKRAQI7I1FDP8nPNV8X/bjqzokBUrJv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B953290DB78BD320CA654ABD84E3851417F39B4B26B3DA8F3DC512C55E23BD1C98279A
sha3_384: f15c129f89f53d07b187b3cfb9c2e68f120e590ffdfcf4c7da7423f37e2500c27530297601d14f18ce5fd7f52ea36d38
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-10-10 00:57:45

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: offDef
FileVersion: 1.0.0.0
InternalName: offDef.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: offDef.exe
ProductName: offDef
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware.CS
MicroWorld-eScanGen:Variant.Zusy.534251
ClamAVWin.Packed.Zusy-10019576-0
FireEyeGeneric.mg.74376c47a96fcf89
SkyhighArtemis!Trojan
McAfeeArtemis!74376C47A96F
Cylanceunsafe
SangforTrojan.Msil.Disabler.Vwp5
K7AntiVirusTrojan ( 005b0b341 )
AlibabaTrojan:MSIL/Disabler.e2b94ce9
K7GWTrojan ( 005b0b341 )
Cybereasonmalicious.f6e16f
ArcabitTrojan.Zusy.D826EB
BitDefenderThetaGen:NN.ZemsilF.36680.dm0@a03q2Wb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Disabler.EC
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Zusy.534251
AvastWin32:WiperX-gen [Trj]
TencentMsil.Trojan.Agent.Ewnw
SophosMal/Disabler-A
VIPREGen:Variant.Zusy.534251
EmsisoftGen:Variant.Zusy.534251 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.aozao
GoogleDetected
Kingsoftmalware.kb.c.885
MicrosoftTrojan:Win32/Phonzy.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataGen:Variant.Zusy.534251
VaristW32/MSIL_Kryptik.JTU.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5575027
ALYacGen:Variant.Zusy.534251
MAXmalware (ai score=80)
MalwarebytesSpyware.LokiBot
RisingTrojan.Disabler!8.B58 (CLOUD)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Disabler.EC!tr
AVGWin32:WiperX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment