comunicadobanesconline.pdf.exe

Komsi

The executable comunicadobanesconline.pdf.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from c11.pcloud.com.
Publisher:
Komsi

Product:
Komsi

Version:
18.2.244.2987

MD5:
76aa2b3808c5393844d15c4ab7555e66

SHA-1:
8b37e2c3486545561a01d7f7eecd188d4b123435

SHA-256:
86d3b91568a313be4c578127f9013601e11dcea23fa83ecaafbb887d6cd392f7

Scanner detections:
11 / 68

Status:
Malware

Analysis date:
4/25/2024 4:04:09 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.186846
263

Arcabit
Trojan.Zusy.D2D9DE
1.0.0.680

Bitdefender
Gen:Variant.Zusy.186846
1.0.20.685

Emsisoft Anti-Malware
Gen:Variant.Zusy.186846
8.16.05.16.05

Fortinet FortiGate
W32/Injector.ADHG!tr
5/16/2016

F-Secure
Gen:Variant.Zusy.186846
11.2016-16-05_2

G Data
Gen:Variant.Zusy.186846
16.5.25

Malwarebytes
Trojan.Zbot.PWS
v2016.05.16.05

MicroWorld eScan
Gen:Variant.Zusy.186846
17.0.0.411

Qihoo 360 Security
QVM05.1.Malware.Gen
1.0.0.1120

Rising Antivirus
Malware.Generic!iMmDKRX6ZmO@3 (Thunder)
23.00.65.16514

File size:
1 MB (1,077,760 bytes)

Product version:
18.2.244.2987

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\comunicadobanesconline.pdf.exe

File PE Metadata
Compilation timestamp:
5/14/2016 1:54:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:3BdlOMYvaUx6xtBiGpbMbyd4mGGdACwvg4:3BLOH3GpbMY4hGdA/

Entry address:
0x8C9D0

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, C0, B7, 48, 00, E8, E1, 9F, F7, FF, 33, C9, B2, 01, A1, 7C, B0, 48, 00, E8, 0B, E8, FF, FF, 33, C9, B2, 01, A1, C8, 28, 46, 00, E8, 99, 18, F9, FF, B2, 01, A1, 1C, 5B, 41, 00, E8, 7D, 70, F7, FF, 33, C9, B2, 01, A1, 6C, E0, 42, 00, E8, D3, 23, FA, FF, 33, C9, B2, 01, A1, 48, EE, 44, 00, E8, 69, 53, FC, FF, 8B, D8, BA, 98, CA, 48, 00, 8B, C3, E8, 47, 06, FB, FF, 33, C0, 55, 68, 54, CA, 48, 00, 64, FF, 30, 64, 89, 20, 8B, C3, E8, 22, AE, FC, FF, 33, C0, 5A, 59, 59, 64...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
558 KB (571,392 bytes)

The file comunicadobanesconline.pdf.exe has been seen being distributed by the following URL.

Remove comunicadobanesconline.pdf.exe - Powered by Reason Core Security