Malware

Zegost.21 (B) (file analysis)

Malware Removal

The Zegost.21 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zegost.21 (B) virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

users.qzone.qq.com
ocsp.dcocsp.cn
crl4.digicert.com
crl3.digicert.com

How to determine Zegost.21 (B)?


File Info:

crc32: B7E3DBCC
md5: a56a6df07044e1cbf29581ed0793fa94
name: A56A6DF07044E1CBF29581ED0793FA94.mlw
sha1: 9c7e9a758f8409583c413bfce02be6c0650f8c40
sha256: 9607262f20a0344c6188e1b7546e88223f3c67c77179dd6fa7c184180c09dc76
sha512: c30ee5eab7f002dfa803481395500ab07c2d9564b5fe6dd663e9e186bfe1eff8bb49ef6fa3f0e15d7e0e5aaa8d5afaf28677e9ed8af18127ec4342b9fadc39ff
ssdeep: 24576:8jVpMQ1MTQmmfXEQl0wwuFQZfpcYRzvcnjAXF:+Vl1dmm8LwwiOBlX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zegost.21 (B) also known as:

K7AntiVirusTrojan ( 003c0f321 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zegost.21
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 003c0f321 )
Cybereasonmalicious.07044e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Enigma.AAA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Bifrose-9837535-0
KasperskyBackdoor.Win32.Farfli.bvto
BitDefenderGen:Variant.Zegost.21
MicroWorld-eScanGen:Variant.Zegost.21
Ad-AwareGen:Variant.Zegost.21
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34722.XCWaaWg2IYpb
TrendMicroTROJ_GEN.R005C0WF321
McAfee-GW-EditionBehavesLike.Win32.Autorun.bc
FireEyeGeneric.mg.a56a6df07044e1cb
EmsisoftGen:Variant.Zegost.21 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1128069
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Zegost.21
AhnLab-V3Trojan/Win32.Xema.C1839847
McAfeeArtemis!A56A6DF07044
MAXmalware (ai score=89)
MalwarebytesMalware.AI.2251104497
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0WF321
RisingMalware.Heuristic!ET#90% (RDMK:cmRtazoYyeoRjIIFcD2+GP5l+/ES)
IkarusVirus.Win32.Heur
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen

How to remove Zegost.21 (B)?

Zegost.21 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment