{445a185a-f60e-8ddb-195a-c091107a7dd3}-ymlygaa.exe

The executable {445a185a-f60e-8ddb-195a-c091107a7dd3}-ymlygaa.exe has been detected as malware by 15 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
c20f580afaf9cd950e438275d99384c9

SHA-1:
aa3aa30b366402748f55f5cd9c63997b696d5ebd

SHA-256:
8b82d368f7f5985ce7d8dea63b6b18a6ebe4f26e8563827b4a04b3593a5ccd9b

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
4/26/2024 6:34:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1869871
865

Avira AntiVirus
TR/Crypt.ZPACK.88407
7.11.173.208

AVG
Trojan horse SHeur4.CCGE
2014.0.4015

Bitdefender
Trojan.GenericKD.1869871
1.0.20.1325

Dr.Web
Trojan.Siggen6.15132
9.0.1.05190

Emsisoft Anti-Malware
Trojan.GenericKD.1869871
8.14.09.22.02

F-Secure
Trojan.GenericKD.1869871
11.2014-22-09_2

G Data
Trojan.GenericKD.1869871
14.9.24

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.1.7.8.0

Kaspersky
Trojan-Spy.Win32.Zbot
15.0.0.494

McAfee
PWSZbot-FADO!2429D9548AF6
5600.6999

MicroWorld eScan
Trojan.GenericKD.1869871
15.0.0.795

NANO AntiVirus
Trojan.Win32.Zbot.dfhkjn
0.28.2.62286

nProtect
Trojan.GenericKD.1869871
14.09.22.01

Sophos
Mal/EncPk-AFC
4.98

File size:
284.3 KB (291,072 bytes)

File type:
Executable application (Win64 EXE)

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
6144:ePMRKYaTJGiChJH48zN5+WzSkzH3MogkSNt6nAfc5vnrAwj1Au6K2ehQspca:KMg/lVCgON5+WRMo3Wt6nAMvnrASAu6E

Entry point:
B2, A5, 6F, FF, FC, FF, FF, FF, FB, FF, FF, FF, 00, 00, FF, FF, 47, FF, FF, FF, FF, FF, FF, FF, BF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FF, FE, FF, FF, F1, E0, 45, F1, FF, 4B, F6, 32, DE, 47, FE, B3, 32, DE, AB, 97, 96, 8C, DF, 8F, 8D, 90, 98, 8D, 9E, 92, DF, 9C, 9E, 91, 91, 90, 8B, DF, 9D, 9A, DF, 8D, 8A, 91, DF, 96, 91, DF, BB, B0, AC, DF, 92, 90, 9B, 9A, D1, F2, F2, F5, DB, FF, FF, FF, FF, FF, FF, FF...
 
[+]

Entropy:
7.9063  (probably packed)