Malware

About “Zusy.409032” infection

Malware Removal

The Zusy.409032 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.409032 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Zusy.409032?


File Info:

name: C59C20381ED151397A50.mlw
path: /opt/CAPEv2/storage/binaries/068382f996ed1364126603603b45d4c41edeb308f6e3a6a309ab4f33c868f22f
crc32: C6C7B9E3
md5: c59c20381ed151397a50c59664e6d451
sha1: 0ebc62ced6ed99fbb6eee088bccc652b59ed3bc4
sha256: 068382f996ed1364126603603b45d4c41edeb308f6e3a6a309ab4f33c868f22f
sha512: bd69c10f8f160aefd096d77f2a263571ae90f7968da358a8162c688088b17efd440adbe9b97dcf213844d909f46c3a97515bb6d5c7c95962e16d741d3445b987
ssdeep: 98304:n17pxWQmtSxSPkSpSNMjUXBdgLHAUfBx1CSsnC2AFVw32+ctPNIpB7F:UQm8WuN7XBdgLHAUf7du6Fd+ctOpB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C4623B313A9414AE4E5CC3AD63B7EE471FA436F8F81B439919B6DC625324E4E312853
sha3_384: 38117f8c395fe5294d1bbf2a0f3c7e1bd6219371834e5279400c0406876564cd18fe4979fc1739d6e2e58fde141b3f41
ep_bytes: 689ab8e9ebe88c0818004233da03f2e9
timestamp: 2021-11-27 21:29:22

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Corporation
FileDescription: Plugin Container for Tor Browser
FileVersion: 78.15.0
ProductVersion: 78.15.0
InternalName: Tor Browser
LegalTrademarks: Mozilla
OriginalFilename: plugin-container.exe
ProductName: Tor Browser
BuildID: 20210507090101
Translation: 0x0000 0x04b0

Zusy.409032 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.409032
FireEyeGeneric.mg.c59c20381ed15139
McAfeeArtemis!C59C20381ED1
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.ed6ed9
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.aoyb
BitDefenderGen:Variant.Zusy.409032
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.409032
SophosML/PE-A + Mal/VMProtBad-A
TrendMicroTROJ_GEN.R002C0RLB21
McAfee-GW-EditionBehavesLike.Win32.Drixed.tc
EmsisoftGen:Variant.Zusy.409032 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.409032
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4834182
ALYacGen:Variant.Zusy.409032
MalwarebytesSpyware.RedLineStealer
TrendMicro-HouseCallTROJ_GEN.R002C0RLB21
RisingTrojan.Generic@ML.99 (RDMK:hDnbPNyHcyHl5SKC5vnANA)
YandexTrojanSpy.Stealer!t4lY8lyYlsY
eGambitUnsafe.AI_Score_89%
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Zusy.409032?

Zusy.409032 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment