Malware

Zusy.464879 (B) (file analysis)

Malware Removal

The Zusy.464879 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.464879 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Tamil
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.464879 (B)?


File Info:

name: 50953CC540919EF5471B.mlw
path: /opt/CAPEv2/storage/binaries/c8ac1d0d9627eb93cd46f81ed97110a5d99bf32cb98f7272aefe2b4b4b2937f6
crc32: 0DFD343A
md5: 50953cc540919ef5471b145391aedbfb
sha1: 199044d7c83305e94b013fcc09835ab97f7462df
sha256: c8ac1d0d9627eb93cd46f81ed97110a5d99bf32cb98f7272aefe2b4b4b2937f6
sha512: 892c7f1fc008df6ca4bda2c7fddfc447ca10d0c47cece7f073d6cc80b52bc154321fdf6bcc7f7ce1ed9298a4c0c68c8b033bbc763c773832ff095b4a89981876
ssdeep: 6144:XKj/q6NigcKaIuMLyeW1SXwhQK5L8iXaxmrqa4AA9J9q+/1P6FL9G3Uifq:XKji6NigdSMG5USDXZqlzJxx6Zwki
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132B4C05372F16833E6321A328E2A86F47A5EF9528F15BBDB2354EA3F09711E1C172741
sha3_384: 564384de16dd30296f3b66f3fbfe6434138cf5d3c70c7b3ab01fef43cb5030c6c89d28fea575dd62e83f0fbc1fc97c08
ep_bytes: e870450000e989feffff8bff558bec8b
timestamp: 2022-01-04 06:36:49

Version Info:

FileDescriptions: NiceIncorporated
FileVersion: 47.44.8.14
InternalNames: HypnoDancer.exe
LegalCopyrights: Night bizon inc.
ProductName: dpfkigosdfjngosdfgno
Translation: 0x4016 0x0534

Zusy.464879 (B) also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PWS.Stealer.33898
FireEyeGeneric.mg.50953cc540919ef5
CAT-QuickHealRansom.Stop.P5
McAfeeArtemis!50953CC54091
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Zusy.464879
CrowdStrikewin/malicious_confidence_100% (D)
SymantecPacked.Generic.528
Elasticmalicious (high confidence)
APEXMalicious
KasperskyVHO:Backdoor.MSIL.Agent.gen
RisingTrojan.Generic@AI.100 (RDML:aFeGHhict5ZwEjg8tfvmpA)
EmsisoftGen:Variant.Zusy.464879 (B)
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hh
Trapminemalicious.high.ml.score
SophosML/PE-A
GoogleDetected
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmVHO:Backdoor.MSIL.Agent.gen
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacGen:Variant.Babar.200506
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGCrypterX-gen [Trj]
AvastCrypterX-gen [Trj]

How to remove Zusy.464879 (B)?

Zusy.464879 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment