Malware

About “Zusy.321820” infection

Malware Removal

The Zusy.321820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.321820 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.blockcypher.com
hjhqmbxyinislkkt.1j9r76.top

How to determine Zusy.321820?


File Info:

crc32: 5885E6BD
md5: fa6e3c4884bb43f33b188bb145b59234
name: FA6E3C4884BB43F33B188BB145B59234.mlw
sha1: 98845685a9fad4a68ad409cc30d69c13fe85a84d
sha256: 9c57b0b532d165cf7f7d5847ce3930b2933269d6d6b731523cb54267015a287c
sha512: bfdb38baa262b1a07e5dd0b35b21563f8a81c26f1663b1e14cca5194dc955dd36dc4da8ae4685bce2c71c4844ccf19f07d08b92c876a22b1688cf0e7dbd68c10
ssdeep: 6144:fR4GbVOUtKXVgcNX3RVR+64R8cog9kqn2oRmgWDVb/ii4mnj0Dt0z:ppVuSG9+VRTCgAx/JQ0z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999 - 2011 SpeedBit Ltd.
FileVersion: 1, 0, 0, 3
CompanyName: Speedbit Ltd.
PrivateBuild: 2599
Comments: 2599
ProductName: DAP Error Report
ProductVersion: 1, 0, 0, 3
FileDescription: DAP Error Report
OriginalFilename: dapxrpt.exe
Translation: 0x0409 0x04b0

Zusy.321820 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11198
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.321820
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1462003
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.ec0d10ef
K7GWHacktool ( 700007861 )
Cybereasonmalicious.884bb4
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/S-502d1467!Eldorado
SymantecRansom.Cerber
ESET-NOD32a variant of Win32/Kryptik.FRVT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Generic-6308667-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.321820
NANO-AntivirusTrojan.Win32.Zerber.eogilk
MicroWorld-eScanGen:Variant.Zusy.321820
TencentMalware.Win32.Gencirc.10b58aaf
Ad-AwareGen:Variant.Zusy.321820
SophosMal/Generic-S
ComodoMalware@#11xi1rlt29b96
BitDefenderThetaGen:NN.ZexaF.34688.Bq0@a0MxIBgi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gh
FireEyeGeneric.mg.fa6e3c4884bb43f3
EmsisoftGen:Variant.Zusy.321820 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129194
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2003816
MicrosoftRansom:Win32/Cerber.K
ArcabitTrojan.Zusy.D4E91C
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.321820
AhnLab-V3Win-Trojan/RansomCrypt.Gen
Acronissuspicious
McAfeeGenericR-JRW!FA6E3C4884BB
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.AACA (CLOUD)
YandexTrojan.GenAsa!qQ6NIot1edw
IkarusTrojan-Ransom.Cerber
FortinetW32/Kryptik.FRVT!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Zusy.321820?

Zusy.321820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment