Trojan

What is “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 6D975C2BD2AC8316C87E.mlw
path: /opt/CAPEv2/storage/binaries/e7af26f43c2660a3c240a4b95748b0a1118c6f955c6b39b3e32b8a233b3292e3
crc32: 57CB3AFE
md5: 6d975c2bd2ac8316c87e025ac8ec7fdf
sha1: babd57c5208bdb1fe05ca532eb0a07e7000bf811
sha256: e7af26f43c2660a3c240a4b95748b0a1118c6f955c6b39b3e32b8a233b3292e3
sha512: 00419a0f81a58b6bd8df223a2e66f9d2e34710711dd4234bf3942f6089a48c1edc54d39abc5a0e45f7a85e477edcfc5d093589e35538e093c5da3387eee38203
ssdeep: 384:qsG0Q64vP1iwOwltkchmPeuaBU3losjuzZ6UwYRGZqI7PoYxi55Dca9ToRi:O0QJFO2tYPP3lLuzZPKqATeYapoRi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T158E2B6597E444CEBEA50173884E7D77A377CF181C6234F62B660BB308A237A1319B16E
sha3_384: 43dcb8dc8ab14bdd09424443accfcd3984016cfd361d28e51dc497454fba21ca17b239590baf935afd4a9133720c6d81
ep_bytes: 57565383ec108b5c24248b7424208b7c
timestamp: 2024-02-09 10:24:23

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.69854
FireEyeGeneric.mg.6d975c2bd2ac8316
SkyhighBehavesLike.Win32.Injector.nm
McAfeeGenericRXWN-OS!6D975C2BD2AC
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.91cc235e
K7GWTrojan ( 005b1a3b1 )
K7AntiVirusTrojan ( 005b1a3b1 )
BitDefenderThetaAI:Packer.2C0C3B5F1E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.DDZ
KasperskyTrojan-Dropper.Win32.Agent.tfsdvk
BitDefenderGen:Variant.Doina.69854
AvastWin32:TrojanX-gen [Trj]
SophosMal/Generic-S
GoogleDetected
F-SecureTrojan.TR/Agent_AGen.idbrs
VIPREGen:Variant.Doina.69854
EmsisoftGen:Variant.Doina.69854 (B)
GDataGen:Variant.Doina.69854
AviraTR/Agent_AGen.idbrs
MAXmalware (ai score=89)
ArcabitTrojan.Doina.D110DE
ZoneAlarmTrojan-Dropper.Win32.Agent.tfsdvk
MicrosoftTrojan:Win32/Phonzy.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R634543
ALYacGen:Trojan.Heur.PT.c46@a0tw!Je
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H07BA24
RisingTrojan.Agent!8.B1E (TFE:5:OFyTIikgXyJ)
IkarusTrojan.Win32.Agent
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment