Trojan

Trojan:Win32/Phonzy.B!ml information

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 4A9AF4C85C063EE51425.mlw
path: /opt/CAPEv2/storage/binaries/549ba45cc7b6092b72964589070dc36e83dd1fa384a636f5f05ba25303149433
crc32: A992B8DB
md5: 4a9af4c85c063ee51425fd1b800ade16
sha1: c40e3f4474af3208d405e591b8aa3e4b2a641e1f
sha256: 549ba45cc7b6092b72964589070dc36e83dd1fa384a636f5f05ba25303149433
sha512: e6b133a8f783f687aeba1faba50be23f4e2107af82f9f0d8194a6fbe800f9f2e07583da33872ba5a5529589c9c75d18757824e5805c3443b6caf6c6c20237c89
ssdeep: 384:VPKbxo3LmVmf9tClfDCmPeuaBU3losjuzZ6UwYRGZqs7PSxjPvHnvGGZckuHLxR5:Ebabtt0NPP3lLuzZPKqkMHvGGekurxR5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B5E2D9997E444CEBE551273C80E7CB76267DF081C6235F62F650A7348B237A2219B27E
sha3_384: 6d3acd2e18ba5dbd9d43682e7fa7b8ce1df36eac77cd8819019ee3c95658917e2f7c70bd17d81254671328c7d6e22854
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 12:33:24

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.503136
FireEyeGeneric.mg.4a9af4c85c063ee5
SkyhighBehavesLike.Win32.Injector.nm
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Generic.55ba16ca
BitDefenderThetaGen:NN.ZedlaF.36744.c46@aa0t78o
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
CynetMalicious (score: 100)
BitDefenderGen:Variant.Fragtor.502863
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Dropper.Uwhl
EmsisoftGen:Variant.Fragtor.503136 (B)
F-SecureTrojan.TR/Dropper.Gen
SophosMal/Generic-S
GDataGen:Variant.Fragtor.502863
AviraTR/Dropper.Gen
ArcabitTrojan.Fragtor.D7AC4F
MicrosoftTrojan:Win32/Phonzy.B!ml
AhnLab-V3Trojan/Win.Generic.R634640
McAfeeGenericRXWN-OO!4A9AF4C85C06
MAXmalware (ai score=82)
RisingTrojan.Agent!8.B1E (CLOUD)
FortinetW32/Agent.DDP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment