Categories: Worm

Worm:Win32/Phorpiex.A (file analysis)

The Worm:Win32/Phorpiex.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Phorpiex.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

rox.drshells.net

How to determine Worm:Win32/Phorpiex.A?


File Info:

crc32: AC2076A6md5: e3c42c6bdb4e0877682e78fe7016d3d5name: E3C42C6BDB4E0877682E78FE7016D3D5.mlwsha1: 25597f9dedcfbf3722fcfea66f54edbd71a4d724sha256: 5b65281389ad19450938f350c9df2db4585448fb08a5d4d7627c243a9f974c4csha512: 2d7c40cce721ebeaf7c7452a867bdc82a21e21d4dd29262d40367ebcf73a286ab1ca4c57ed8072228d457c3f9d3c91aeca458816fa44349c944e3c335f5a2713ssdeep: 1536:SKNd+f6ChsQY6makJxcqFqREtTXllfmOH5DZ:9z8sQjCJxh0REpXllfmOH/type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0InternalName: loFileVersion: 1.06.0005CompanyName: Martinique Lazarus Coleridge Diophantine NedLegalTrademarks: I've CyclopsComments: Lund SundayProductName: Nelsen DurerProductVersion: 1.06.0005FileDescription: Mardi HomOriginalFilename: lo.exe

Worm:Win32/Phorpiex.A also known as:

Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Heur.PonyStealer.gm0@nuzaEloi
FireEye Generic.mg.e3c42c6bdb4e0877
Qihoo-360 Win32/Trojan.Dropper.1eb
ALYac Gen:Heur.PonyStealer.gm0@nuzaEloi
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
K7AntiVirus P2PWorm ( 004bdc981 )
BitDefender Gen:Heur.PonyStealer.gm0@nuzaEloi
K7GW P2PWorm ( 004bdc981 )
Cybereason malicious.bdb4e0
Cyren W32/VBInject.1!Generic
Symantec ML.Attribute.HighConfidence
TotalDefense Win32/VBInject.O!generic
APEX Malicious
Avast Win32:Patched-AML
ClamAV Win.Worm.Phorpiex-7163127-0
Kaspersky Trojan-Dropper.Win32.Sysn.aduc
Alibaba TrojanDropper:Win32/IRCBot.e31f0cc5
NANO-Antivirus Trojan.Win32.Sysn.fgvmqp
ViRobot Trojan.Win32.A.VBKrypt.98304.E
Tencent Win32.Trojan-dropper.Sysn.Akym
Ad-Aware Gen:Heur.PonyStealer.gm0@nuzaEloi
Sophos ML/PE-A + Mal/VBCheMan-C
Comodo TrojWare.Win32.Agent.~kst@3yda0g
F-Secure Trojan.TR/Patched.Ren.Gen
DrWeb Win32.HLLW.Phorpiex.5
Zillya Trojan.VBKrypt.Win32.71071
TrendMicro WORM_AUTORUN.HDT
McAfee-GW-Edition Trojan-FBIP!E3C42C6BDB4E
Emsisoft Gen:Heur.PonyStealer.gm0@nuzaEloi (B)
Ikarus Virus.Win32.Ramnit
Jiangmin Worm/AutoRun.alsd
Avira TR/Patched.Ren.Gen
MAX malware (ai score=100)
Antiy-AVL Worm/Win32.AutoRun
Microsoft Worm:Win32/Phorpiex.A
Arcabit Trojan.PonyStealer.E77C99
SUPERAntiSpyware Trojan.Agent/Gen-Falleg[T]
ZoneAlarm Trojan-Dropper.Win32.Sysn.aduc
GData Gen:Heur.PonyStealer.gm0@nuzaEloi
Cynet Malicious (score: 100)
Acronis suspicious
McAfee Trojan-FBIP!E3C42C6BDB4E
VBA32 BScope.Worm.WBNA
Malwarebytes Nimnul.Virus.FileInfector.DDS
Panda Generic Malware
ESET-NOD32 Win32/AutoRun.IRCBot.HO
TrendMicro-HouseCall WORM_AUTORUN.HDT
Rising Worm.Phorpiex!8.48D (TFE:3:6uY6ZXkOQEE)
Yandex Trojan.GenAsa!ShdSGCqlIog
SentinelOne Static AI – Malicious PE
Fortinet W32/AutoRun.C!worm
BitDefenderTheta AI:Packer.CAB5237220
AVG Win32:Patched-AML
Paloalto generic.ml
CrowdStrike win/malicious_confidence_70% (D)

How to remove Worm:Win32/Phorpiex.A?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan:Win32/Dingu.A (file analysis)

The Trojan:Win32/Dingu.A is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago

Trojan:Win32/Miuref.B malicious file

The Trojan:Win32/Miuref.B is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

About “Win32:Hiloti-K [Trj]” infection

The Win32:Hiloti-K [Trj] is considered dangerous by lots of security experts. When this infection is…

40 mins ago

Worm.Win32.WBNA.bwbx information

The Worm.Win32.WBNA.bwbx is considered dangerous by lots of security experts. When this infection is active,…

44 mins ago

Win32/Kryptik.RHB (file analysis)

The Win32/Kryptik.RHB is considered dangerous by lots of security experts. When this infection is active,…

59 mins ago

Strictor.263229 (B) removal tips

The Strictor.263229 (B) is considered dangerous by lots of security experts. When this infection is…

59 mins ago