aaab0d4.tmp

The file aaab0d4.tmp has been detected as a potentially unwanted program by 36 anti-malware scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
0a4095e3235afbe71c6f4c99529d57de

SHA-1:
33da3de0ca96f32ef0d484c53a782ad0e81ddbb5

SHA-256:
0ed904c4e6a14f681157c3cbf62358aac023f67690e8929da5e7ef2cb9f2e8e9

Scanner detections:
36 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 2:08:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Inject.IA
865

Agnitum Outpost
Trojan.Wigon
7.1.1

AhnLab V3 Security
Trojan/Win32.Downloader
2014.09.18

Avira AntiVirus
TR/Proxy.Horst.Gen
7.11.173.16

avast!
Win32:DNSChanger-ZZ [Trj]
2014.9-140922

AVG
Win32/DH{IIEOJYETeW4TFw}
2015.0.3343

Baidu Antivirus
Trojan.Win32.Wigon
4.0.3.14922

Bitdefender
Trojan.Inject.IA
1.0.20.1325

Bkav FE
HW32.Paked
1.3.0.4959

Comodo Security
UnclassifiedMalware
19547

Emsisoft Anti-Malware
Trojan.Inject.IA
8.14.09.22.12

ESET NOD32
Win32/Wigon.PH (variant)
8.10435

Fortinet FortiGate
W32/IRIEN.DDF!tr.dldr
9/22/2014

F-Prot
New
v6.4.7.1.166

F-Secure
Trojan.Inject.IA
11.2014-22-09_2

G Data
Trojan.Inject.IA
14.9.24

IKARUS anti.virus
Gen.Trojan
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.183.13407

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3212

Malwarebytes
Backdoor.Bot
v2014.09.22.12

McAfee
RDN/Downloader.a!qx
5600.6999

Microsoft Security Essentials
TrojanDownloader:Win32/Cutwail.CB
1.11005

MicroWorld eScan
Trojan.Inject.IA
15.0.0.795

NANO AntiVirus
Trojan.Win32.Zbot.cyxirc
0.28.2.62151

Norman
Inject.CCWS
11.20140922

nProtect
Trojan.Inject.IA
14.09.17.01

Panda Antivirus
Trj/Genetic.gen
14.09.22.12

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
TrojanSpy.Zbot.r4
9.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.16C77A53!382171731
23.00.65.14920

Sophos
Mal/Emogen-Y
4.98

Trend Micro House Call
TROJ_CUTWAIL.YAR
7.2.265

Trend Micro
TROJ_CUTWAIL.YAR
10.465.22

Vba32 AntiVirus
SScope.Trojan.Zbot.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
33220

Zillya! Antivirus
Trojan.Zbot.Win32.156862
2.0.0.1926

File size:
229.5 KB (235,008 bytes)

Common path:
C:\users\{user}\appdata\local\temp\aaab0d4.tmp

File PE Metadata
Compilation timestamp:
10/31/2004 11:24:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:lVHef7xuqGMYARItjnhEzgg8CyTuiy0o8Lk2dC1sq1t+Q05oyGaKwjPOymTRvsbc:lI4MBIx6kr31+t+Q02SKwjPTkR0y

Entry address:
0x2020

Entry point:
55, 8B, EC, 81, EC, 90, 0E, 00, 00, E8, 32, 0C, 00, 00, 89, 85, 6C, FE, FF, FF, 8B, 85, 6C, FE, FF, FF, 50, E8, E0, 0C, 00, 00, 83, C4, 04, 68, 50, 1A, 30, 04, FF, 15, 78, 50, 30, 04, 8D, 8D, 70, FE, FF, FF, 51, 68, 02, 02, 00, 00, E8, A7, EF, FF, FF, 85, C0, 74, 05, E9, 84, 04, 00, 00, 6A, 00, FF, 15, 48, 51, 30, 04, E8, EB, F2, FF, FF, A2, 76, B2, 33, 04, 6A, 00, 6A, 01, 6A, 01, 6A, 00, FF, 15, 64, 50, 30, 04, A3, 7C, B2, 33, 04, 68, 08, 02, 00, 00, 6A, 00, 68, 40, AB, 33, 04, E8, 62, F8, FF, FF, 83, C4...
 
[+]

Entropy:
7.5396

Developed / compiled with:
Microsoft Visual C++

Code size:
16 KB (16,384 bytes)

Remove aaab0d4.tmp - Powered by Reason Core Security