Trojan

Trojan:Win32/Phonzy.B!ml information

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 227470A3138840556D9F.mlw
path: /opt/CAPEv2/storage/binaries/10990c7d420262d163da0f026ad508f28beb7f16e31b50545c9e72a59ba81afc
crc32: 14C9440D
md5: 227470a3138840556d9f562845676dab
sha1: 58890735865abcdb69d85fdae1b1025ec1921f58
sha256: 10990c7d420262d163da0f026ad508f28beb7f16e31b50545c9e72a59ba81afc
sha512: 75dcb4ac7ff0dc7f163cdb18ba78a0ca7c23ad1bcebd3243641ad3795f34860988f1d853a75a051599075351eff9fc17ec41a729b021c60532432b9dfef4e8ce
ssdeep: 196608:GFE2N/R9MEA1KhN2qSADepCUDdWoTnm6ZKADQwQDRv:0N/cKVZDepCUDdWIm6uv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1867633B221B2CAB3E1913A79A624E13F9B9B7B76513F146430829CCE7D11983E454FD3
sha3_384: 37a7459f085fb5ab9b9c47b78d4ac8850f0e37edbe602b427d316dca6ea5207f7ae4da568f3e80b87ac9ce6a6128e05e
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-02-11 18:19:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: EMON Tools Ultra Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Munp.1
FireEyeGen:Heur.Munp.1
SkyhighBehavesLike.Win32.BadFile.wc
McAfeeArtemis!227470A31388
Cylanceunsafe
SangforTrojan.Win32.Agent.Vix0
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Ekstak.55bf5a06
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.avrti
BitDefenderGen:Heur.Munp.1
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Gjgl
SophosMal/Generic-S
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Munp.1 (B)
IkarusTrojan.Win32.FakeAV
GDataGen:Heur.Munp.1
VaristW32/Trojan.JCJY-6154
ArcabitTrojan.Munp.1
ZoneAlarmTrojan.Win32.Ekstak.avrti
MicrosoftTrojan:Win32/Phonzy.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5587429
MAXmalware (ai score=88)
MalwarebytesBackdoor.TVRat.Dropper
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0DBB24
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment