{30e26bfe-69f9-4808-baac-624ad041c7eb}

The file {30e26bfe-69f9-4808-baac-624ad041c7eb} has been detected as malware by 34 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
5dbf633241d49558742e468e650e79ca

SHA-1:
c2bac9de903333355222fda19f2475f9c0f20aa7

SHA-256:
ee8ee20055357465e4c73dcaf1e1d8bb9277b8a10d0c70ffaebbf722bc69d812

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/26/2024 1:23:20 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1612080
856

Agnitum Outpost
Trojan.DL.Wauchos
7.1.1

AhnLab V3 Security
Trojan/Win32.Wauchos
14.10.02

Avira AntiVirus
TR/Gamarue.A.285
7.11.141.12

avast!
Win32:Malware-gen
2014.9-141002

AVG
Luhe.Fiha.A
2015.0.3334

Baidu Antivirus
Trojan.Win32.Wauchos
4.0.3.14102

Bitdefender
Trojan.GenericKD.1612080
1.0.20.1375

Comodo Security
TrojWare.Win32.Kryptik.BXN
18039

Dr.Web
BackDoor.Andromeda.267
9.0.1.0275

Emsisoft Anti-Malware
Backdoor.Win32.Androm
8.14.10.02.04

ESET NOD32
Win32/TrojanDownloader.Wauchos
8.9631

Fortinet FortiGate
W32/Wauchos.Z!tr.dldr
10/2/2014

F-Secure
Trojan.GenericKD.1612080
11.2014-02-10_5

G Data
Trojan.GenericKD.1612080
14.10.24

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.2.2.29

K7 AntiVirus
Trojan-Downloader
13.176.11637

Malwarebytes
Backdoor.Bot
v2014.10.02.04

McAfee
RDN/Generic PWS.y!yx
5600.6990

Microsoft Security Essentials
Worm:Win32/Gamarue
1.10401

MicroWorld eScan
Trojan.GenericKD.1612080
15.0.0.825

NANO AntiVirus
Trojan.Win32.Andromeda.cvxxkm
0.28.0.58873

Norman
Suspicious_Gen4.FZQFY
11.20141002

nProtect
Trojan.GenericKD.1612080
14.04.03.01

Panda Antivirus
Generic Malware
14.10.02.04

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
Worm.Gamarue.sa
10.14.12.00

Sophos
Troj/Wonton-AM
4.98

Total Defense
Win32/Zbot.eJdILM
37.0.10855

Trend Micro House Call
BKDR_ANDROM.SMCO
7.2.275

Trend Micro
BKDR_ANDROM.SMCO
10.465.02

VIPRE Antivirus
Trojan.Win32.Zbot.htk
27982

ViRobot
Trojan.Win32.U.Agent.172032
2011.4.7.4223

XVirus List
Win32.Detected
2.10.2

File size:
168 KB (172,032 bytes)

File PE Metadata
Compilation timestamp:
3/20/2014 4:56:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
3072:lf3XZUuOtRbT+T0mcqPdC5kDPCMIVbITBe1tDxwXq:l3JhOtJ+Ttco/U

Entry address:
0x8B1D

Entry point:
E8, 08, 14, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 25, 83, 78, 10, 03, 75, 1F, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 1B, 3D, 21, 05, 93, 19, 74, 14, 3D, 22, 05, 93, 19, 74, 0D, 3D, 00, 40, 99, 01, 74, 06, 33, C0, 5D, C2, 04, 00, E8, 15, 1E, 00, 00, CC, 68, 27, 8B, 40, 00, E8, F0, 1A, 00, 00, 59, 33, C0, C3, 55, 8B, EC, 56, E8, 39, 03, 00, 00, 8B, F0, 85, F6, 0F, 84, 45, 01, 00, 00, 8B, 56, 5C, 8B, CA, 57, 8B, 7D, 08, 39, 39, 74, 0D, 83, C1, 0C, 8D, 82, 90, 00...
 
[+]

Code size:
120 KB (122,880 bytes)

Remove {30e26bfe-69f9-4808-baac-624ad041c7eb} - Powered by Reason Core Security