1bo84b8.tmp

The file 1bo84b8.tmp has been detected as a potentially unwanted program by 37 anti-malware scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
6fb7bb86a094ded9d1b40ef634edf351

SHA-1:
045275af2f5439932f24965b9558c7d4fd84cda7

SHA-256:
4a29f9366d0645425099033fe800bf4b7a96995457aca9acd5c27ed45896562b

Scanner detections:
37 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:42:25 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.IA
835

Agnitum Outpost
Trojan.Wigon
7.1.1

AhnLab V3 Security
Trojan/Win32.Downloader
2014.10.08

Avira AntiVirus
TR/Proxy.Horst.Gen
7.11.177.26

avast!
Win32:DNSChanger-ZZ [Trj]
2014.9-141022

AVG
Win32/DH{IIEOJYETeW4TFyM}
2015.0.3313

Baidu Antivirus
Trojan.Win32.Wigon
4.0.3.141022

Bitdefender
Trojan.Inject.IA
1.0.20.1475

Bkav FE
HW32.Paked
1.3.0.4959

Comodo Security
UnclassifiedMalware
19733

Emsisoft Anti-Malware
Trojan.Inject.IA
8.14.10.22.03

ESET NOD32
Win32/Wigon.PH (variant)
8.10525

Fortinet FortiGate
W32/IRIEN.DDF!tr.dldr
10/22/2014

F-Prot
New
v6.4.7.1.166

F-Secure
Trojan.Inject.IA
11.2014-22-10_4

G Data
Trojan.Inject.IA
14.10.24

IKARUS anti.virus
Gen.Trojan
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13611

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3062

Malwarebytes
Spyware.Password
v2014.10.22.03

McAfee
Generic.sr
5600.6969

Microsoft Security Essentials
TrojanDownloader:Win32/Cutwail.CB
1.11005

MicroWorld eScan
Trojan.Inject.IA
15.0.0.885

NANO AntiVirus
Trojan.Win32.Zbot.cyxksc
0.28.2.62483

Norman
Troj_Generic.UYVXG
11.20141022

nProtect
Trojan.Inject.IA
14.10.07.01

Panda Antivirus
Adware/SecurityProtection
14.10.22.03

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
TrojanSpy.Zbot.r4
10.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.16C9C4B3!382321843
23.00.65.141020

Sophos
Mal/Emogen-Y
4.98

Trend Micro House Call
Mal_DLDER
7.2.295

Trend Micro
Mal_DLDER
10.465.22

Vba32 AntiVirus
SScope.Trojan.Zbot.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33720

ViRobot
Trojan.Win32.A.Zbot.235008.BT
2011.4.7.4223

Zillya! Antivirus
Trojan.Zbot.Win32.160787
2.0.0.1945

File size:
229.5 KB (235,008 bytes)

Common path:
C:\users\{user}\appdata\local\temp\1bo84b8.tmp

File PE Metadata
Compilation timestamp:
6/28/2009 6:06:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:17Hef7xuqGMYARItjnhEzgg8o9Ngi8QwyTuiy0o8Lk2dC1sq1t+Q05s3c3j9/Zsw:1m4MBIx6ko9Ngi8QV31+t+Q0e3c3jky

Entry address:
0x2020

Entry point:
55, 8B, EC, 81, EC, 90, 0E, 00, 00, E8, 32, 0C, 00, 00, 89, 85, 6C, FE, FF, FF, 8B, 85, 6C, FE, FF, FF, 50, E8, E0, 0C, 00, 00, 83, C4, 04, 68, 50, 1A, 30, 04, FF, 15, 78, 50, 30, 04, 8D, 8D, 70, FE, FF, FF, 51, 68, 02, 02, 00, 00, E8, A7, EF, FF, FF, 85, C0, 74, 05, E9, 84, 04, 00, 00, 6A, 00, FF, 15, 48, 51, 30, 04, E8, EB, F2, FF, FF, A2, 06, B2, 33, 04, 6A, 00, 6A, 01, 6A, 01, 6A, 00, FF, 15, 64, 50, 30, 04, A3, 0C, B2, 33, 04, 68, 08, 02, 00, 00, 6A, 00, 68, D0, AA, 33, 04, E8, 62, F8, FF, FF, 83, C4...
 
[+]

Entropy:
7.5361

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

Remove 1bo84b8.tmp - Powered by Reason Core Security