Trojan

Should I remove “Trojan:Win32/Phonzy.B!ml”?

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: 7DFA04C45A4335A440B9.mlw
path: /opt/CAPEv2/storage/binaries/a173eed986fa4d047cb5e5a15caa8d594389cf663472ceaaa6aff23be3fc3988
crc32: FD067204
md5: 7dfa04c45a4335a440b96db5773cd501
sha1: 73e753e390253206dac52d3ff23ea727dd490dcc
sha256: a173eed986fa4d047cb5e5a15caa8d594389cf663472ceaaa6aff23be3fc3988
sha512: ccce49ba5a65b6f986db05a7b53b619f840fc97de3ac7519b977375a4295fadbba4b7202130f7f2825383ee7d27ff6825be74f9d6e2cdd2f1d900fc24851abde
ssdeep: 768:75D7/AAiIbhnQ2gTaWSxjAuEDFAnA1tLRNk2djaYoCMHosJYJJGCJNjD:75D7/3ZgVqA2uBNdSCMuD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178434A20B7C28472E27395B508F6D2D1543AFF51AB3A81DF72983B650E723C18975F2A
sha3_384: c2ba3febde4cb0e22d1e239f3e3a2bda1452ad18a0d79dd60e5a2590db6f8fb1ef3323c50b96204932066bcd418a3f74
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.535043
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.qh
McAfeePWSZbot-FEV!7DFA04C45A43
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4445380
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005616531 )
K7GWTrojan ( 005616531 )
Cybereasonmalicious.45a433
BaiduWin32.Trojan-Spy.Zbot.a
VirITTrojan.Win32.Crypt2.AXYW
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BIYN
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Malware.Ppatre-6996988-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Zusy.535043
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TACHYONTrojan-Downloader/W32.Upatre.60428.H
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoad3.28161
VIPREGen:Variant.Zusy.535043
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7dfa04c45a4335a4
EmsisoftGen:Variant.Zusy.535043 (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojan/Buzus.bnwn
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
VaristW32/RopProof.H.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.ropf
MicrosoftTrojan:Win32/Phonzy.B!ml
XcitiumTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
ArcabitTrojan.Zusy.D82A03
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.1DJ5MGL
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5580656
Acronissuspicious
VBA32Trojan.Fareit.2883
ALYacGen:Variant.Zusy.535043
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/GdSda.A
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!dUSBw1EZjpA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.BIYN!tr
BitDefenderThetaAI:Packer.6D5B77C21F
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment