5b75.tmp

The file 5b75.tmp has been detected as malware by 9 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
b533a478e316ea8b5bcb494090d6e9e3

SHA-1:
3f37fed7819113de5fc211b250102059c94e53a1

SHA-256:
caa9bd169a564217f417e03238b8fac33eda1df33ea8c122e9a620d06a151f48

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
4/23/2024 10:13:33 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Trojan/Win32.Tinba
2015.07.08

Avira AntiVirus
TR/Spy.ZBot.xbbooj
8.3.1.6

avast!
Win32:Trojan-gen
150602-1

AVG
Generic36
2016.0.3055

Dr.Web
Trojan.PWS.Tinba.176
9.0.1.05190

K7 AntiVirus
Trojan
13.205.16483

NANO AntiVirus
Trojan.Win32.Zbot.dsoijm
0.30.24.2487

Sophos
Mal/Zbot-TV
4.98

ViRobot
Trojan.Win32.Agent.114688.CL[h]
2014.3.20.0

File size:
40.8 KB (41,772 bytes)

Common path:
C:\users\{user}\appdata\local\temp\5b75.tmp

File PE Metadata
Compilation timestamp:
6/2/2015 12:37:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:opfQxO/+EfViPKs0M4HjDD4aIwl3XdIXKdVxGMvCpcwS739HuDjWDvhU:oPL4PKDM4HU1wl3XdIXK5PGcL9HuDiDm

Entry address:
0x8B94

Entry point:
55, 8B, EC, 6A, FF, 68, F0, 9A, 40, 00, 68, D0, 8D, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, 5F, 57, FF, 15, 88, 93, 40, 00, 59, 83, 0D, 9C, B1, 40, 00, FF, 83, 0D, A0, B1, 40, 00, FF, FF, 15, 8C, 93, 40, 00, 8B, 0D, 90, B1, 40, 00, 89, 08, FF, 15, 90, 93, 40, 00, 8B, 0D, 8C, B1, 40, 00, 89, 08, A1, 94, 93, 40, 00, 8B, 00, A3, 98, B1, 40, 00, E8, CA, 01, 00, 00, 39, 1D, B0, B0, 40, 00, 75, 0C, 68, CC, 8D, 40, 00, FF, 15...
 
[+]

Entropy:
4.8615

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
32 KB (32,768 bytes)

Remove 5b75.tmp - Powered by Reason Core Security