{blocked}.zip

The file {blocked}.zip has been detected as malware by 26 anti-virus scanners. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from yanaki.net.
MD5:
1a9fade04f8a83f549c8d71aa99b1d61

SHA-1:
c188c1f3ce23d2407783f4279d93ccfd35ee3144

SHA-256:
3578bb81a1556f92bebd37b6e76ab7706f489019ccb27c0f79167c470a0d6063

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/1/2024 9:21:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Aspxor.2
5710929

Agnitum Outpost
Trojan.DL.Zortob
7.1.1

Avira AntiVirus
TR/Crypt.XPACK.Gen7
8.3.1.6

Arcabit
Trojan.Aspxor.2
1.0.0.425

avast!
Win32:GenMalicious-AMT [Trj]
2014.9-150624

AVG
Downloader.Generic14
2016.0.3069

Bitdefender
Gen:Variant.Aspxor.2
1.0.20.875

Dr.Web
infected with BackDoor.Kuluoz.4
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Aspxor
10.0.0.5366

ESET NOD32
Win32/TrojanDownloader.Zortob.H trojan
7.0.302.0

Fortinet FortiGate
W32/Kryptik.CLRU!tr
6/24/2015

F-Prot
W32/A-7c1c957e
v6.4.7.1.166

F-Secure
Gen:Variant.Aspxor.2
11.2015-24-06_4

G Data
Gen:Variant.Aspxor
15.6.25

IKARUS anti.virus
Trojan.Win32.Tipp
t3scan.1.9.5.0

K7 AntiVirus
NetWorm
13.205.16334

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1839

McAfee
Trojan.Downloader-FAII!5C041594A962
17.6.569.0

Microsoft Security Essentials
Threat.Undefined
1.199.3383.0

MicroWorld eScan
Gen:Variant.Aspxor.2
16.0.0.525

NANO AntiVirus
Trojan.Win32.Kuluoz.dfptca
0.30.24.2086

Norman
Gen:Variant.Aspxor.2
02.06.2015 14:23:46

Quick Heal
TrojanDownloader.Kuluoz.D5
6.15.14.00

Sophos
Virus 'Mal/Wonton-W'
5.15

Total Defense
Win32/Kuluoz.cdSQTYC
37.1.62.1

VIPRE Antivirus
Trojan.Win32.Kuluoz.dm
41404

File size:
70 KB (71,653 bytes)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\e-zpass_germantown_20876.zip

The file {blocked}.zip has been seen being distributed by the following URL.

Remove {blocked}.zip - Powered by Reason Core Security