Trojan

Trojan:Win32/Phonzy.B!ml malicious file

Malware Removal

The Trojan:Win32/Phonzy.B!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phonzy.B!ml virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan:Win32/Phonzy.B!ml?


File Info:

name: B15B1019181F5E71064A.mlw
path: /opt/CAPEv2/storage/binaries/9bf2ae1608a0dc375675469bf117ae23077a97bf589a73d30262b443f09b7eeb
crc32: 8B882B71
md5: b15b1019181f5e71064abb918730f6ac
sha1: f574d1b625e26b90e634abe9d2fd1019658c6cd5
sha256: 9bf2ae1608a0dc375675469bf117ae23077a97bf589a73d30262b443f09b7eeb
sha512: 5d8060668d577ef523acd928a72d05ffee358c74347ae7c4e1e7c897f7f9d75735a2a2a1a72ecc16e14cbfc518fcff28be9dc604f0bb11662646bcdaa192ed02
ssdeep: 24576:zO6wcZosNZbpvGczE/5eqSh5fJ5qfNzC+hkjJcBnMFoKxjZO6kQ1Aw3x0haeL5wo:d5NZbpvGczE/5e/h5fJ5cNzC+hkjJcBV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB55DF1ABAE1D03DCD33C0BE9556D228566BFC600CD2459BA3E8D77DBEB06417523B22
sha3_384: 30e9c188031c323416afbab2de9eecd16906aea867e27436510cc842a559c20c3b7b47f9d847e15ad7cbb5411ea2f0a7
ep_bytes: e834080000e98efeffffcccccc538b44
timestamp: 2016-08-16 12:33:48

Version Info:

CompanyName: Spotify Ltd
FileDescription: SpotifyInstaller
FileVersion: 0,0,0,0
InternalName: SpotifyInstaller
LegalCopyright: Copyright (c) 2016, Spotify Ltd
OriginalFilename: SpotifyInstaller.exe
ProductName: Spotify
ProductVersion: 1.0.36.124.g1cba1920
Translation: 0x0000 0x04b0

Trojan:Win32/Phonzy.B!ml also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.Dropper.tc
McAfeeArtemis!B15B1019181F
BitDefenderThetaGen:NN.ZexaF.36802.rz3@aOQO!cni
APEXMalicious
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.80 (RDML:4zS1P2Vb3mWMRedSp+2rWw)
Trapminemalicious.high.ml.score
JiangminTrojan.Banker.NeutrinoPOS.mg
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Phonzy.B!ml
GoogleDetected
VBA32TrojanBanker.NeutrinoPOS
IkarusTrojan-Banker.Win32.NeutrinoPOS
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Phonzy.B!ml?

Trojan:Win32/Phonzy.B!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment