1ad7.tmp

The file 1ad7.tmp has been detected as malware by 19 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
8f5d97d9c1994d38b39f4ed47f72c3f4

SHA-1:
b923dde4511b432de6e1fc4052bc90b545fa4478

SHA-256:
a31db7120ca425c59b562719ea3087eb56226223a15b7e2ceea88fdfe9c00bcc

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
4/26/2024 5:48:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Tinba
2015.07.08

avast!
Win32:Rootkit-gen [Rtk]
150602-1

AVG
Crypt4
2016.0.3055

Dr.Web
Trojan.Encoder.514
9.0.1.05190

ESET NOD32
Win32/Injector.CCJY trojan
7.0.302.0

Fortinet FortiGate
W32/Injector.CCIS!tr
7/7/2015

IKARUS anti.virus
Trojan.Win32.Injector
t3scan.1.9.5.0

McAfee
Emotet-FAC!8F5D97D9C199
5600.6711

Microsoft Security Essentials
Threat.Undefined
1.201.601.0

NANO AntiVirus
Trojan.Win32.Blocker.dsqolv
0.30.24.2487

Panda Antivirus
Trj/Genetic.gen
15.07.07.05

Quick Heal
TrojanPWS.Zbot.A4
7.15.14.00

Rising Antivirus
PE:Malware.Obscure/Heur!1.9E03
23.00.65.15705

Sophos
Mal/Zbot-TW
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Infector
9768

Vba32 AntiVirus
Hoax.Blocker
3.12.26.4

VIPRE Antivirus
Threat.5173190
40786

ViRobot
Trojan.Win32.Agent.143360.BP[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Zbot.Win32.180597
2.0.0.2272

File size:
158.7 KB (162,551 bytes)

Common path:
C:\users\{user}\appdata\local\temp\1ad7.tmp

File PE Metadata
Compilation timestamp:
6/7/2015 1:11:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:Mmmw6SRQNKDAkRHqCcNMUy+XUANhzD4yp2MmQKMFxsymN3z+f:ww3kKwCEy+kAQQfGMf

Entry address:
0x7414

Entry point:
55, 8B, EC, 6A, FF, 68, 58, 8C, 40, 00, 68, 78, 75, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 7C, 83, 40, 00, 59, 83, 0D, 8C, A1, 40, 00, FF, 83, 0D, 90, A1, 40, 00, FF, FF, 15, 80, 83, 40, 00, 8B, 0D, 80, A1, 40, 00, 89, 08, FF, 15, 84, 83, 40, 00, 8B, 0D, 7C, A1, 40, 00, 89, 08, A1, 88, 83, 40, 00, 8B, 00, A3, 88, A1, 40, 00, E8, 22, 01, 00, 00, 39, 1D, A0, A0, 40, 00, 75, 0C, 68, A2, 75, 40, 00, FF, 15, 8C, 83...
 
[+]

Entropy:
7.5031

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
28 KB (28,672 bytes)

Remove 1ad7.tmp - Powered by Reason Core Security