c09fbb61046e9beb59c3f9acf9852c0e.exe

OOO Kango

The application c09fbb61046e9beb59c3f9acf9852c0e.exe by OOO Kango has been detected as a potentially unwanted program by 31 anti-malware scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
IObit  (signed by OOO Kango)

Version:
1.2.0.271

MD5:
c09fbb61046e9beb59c3f9acf9852c0e

SHA-1:
ee86f334a25617732987e7fcd1efaab996352422

SHA-256:
2cf44ff98ecb4492ab364341801b718bdd0df6829ec236c0a6971faf90b24f83

Scanner detections:
31 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 5:20:23 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2479255
536

Agnitum Outpost
TrojanSpy.Recam
7.1.1

AhnLab V3 Security
Backdoor/Win32.NetWiredRC
2015.07.24

Arcabit
Trojan.Generic.D25D497
1.0.0.425

avast!
MSIL:Crypt-YE [Trj]
2014.9-150817

AVG
MSIL8
2016.0.3014

Baidu Antivirus
Trojan.Win32.Recam
4.0.3.15817

Bitdefender
Trojan.GenericKD.2479255
1.0.20.1145

Bkav FE
W32.Clod15c.Trojan
1.3.0.6979

Dr.Web
BackDoor.Wirenet.5
9.0.1.0229

Emsisoft Anti-Malware
Trojan.GenericKD.2479255
8.15.08.17.10

ESET NOD32
MSIL/Injector.JYW (variant)
9.11986

Fortinet FortiGate
MSIL/Injector.JZJ!tr
8/17/2015

F-Secure
Trojan.GenericKD.2479255
11.2015-17-08_2

G Data
Trojan.GenericKD.2479255
15.8.25

IKARUS anti.virus
Trojan.Crypt
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.207.16662

Kaspersky
Trojan-Spy.Win32.Recam
14.0.0.1565

McAfee
RDN/Generic BackDoor!bdn
5600.6670

Microsoft Security Essentials
Backdoor:Win32/NetWiredRC.C
1.1.11903.0

MicroWorld eScan
Trojan.GenericKD.2479255
16.0.0.687

NANO AntiVirus
Trojan.Win32.Recam.dsujrn
0.30.24.2668

nProtect
Trojan.GenericKD.2479255
15.07.23.01

Panda Antivirus
Trj/CI.A
15.08.17.10

Qihoo 360 Security
Win32/Trojan.d0d
1.0.0.1015

Quick Heal
Trojan.Kovter.RN3
8.15.14.00

Reason Heuristics
PUP.Kango.OOOKango (M)
15.8.17.22

Sophos
Mal/MSIL-NX
4.98

Trend Micro
TROJ_GEN.R03AC0DFH15
10.465.17

VIPRE Antivirus
Lookslike.MSIL.Zbot.a
42266

Zillya! Antivirus
Trojan.Recam.Win32.488
2.0.0.2311

File size:
498.3 KB (510,240 bytes)

Product version:
1.0.0.0

Copyright:
Copyright(C) 2012-2013

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2013 8:00:00 AM

Valid to:
12/2/2016 7:59:59 AM

Subject:
CN=OOO Kango, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=OOO Kango, L=Novosibirsk, S=Novosibirsk, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0239634E379703CC4FB0A20568600B2D

File PE Metadata
Compilation timestamp:
6/3/2015 11:54:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:aQUptMozwTvu6uCpaA+GYayyX+OtP7YACFBEEDwpNqmeLy9Rn4MKhx:as5u24QYhhOl0ACnDwzqmeLy9R4MKhx

Entry address:
0x572DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4699

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
344 KB (352,256 bytes)

Remove c09fbb61046e9beb59c3f9acf9852c0e.exe - Powered by Reason Core Security