dot__57.exe

The executable dot__57.exe has been detected as malware by 26 anti-virus scanners. The file has been seen being downloaded from ftp.getmovingsupplies.com.
MD5:
51bb5298e2923d24d215056d50d059d6

SHA-1:
5eea86f7f28506913fde6ecc2817598d005c7982

SHA-256:
0a1fd414b5ab62063af9e860510251367f68b260201e9bc953e45ff8a562ce6c

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
4/26/2024 8:05:52 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Spyware/Win32.Zbot
2013.08.31

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.99.48

avast!
Win32:Zbot-RTX [Trj]
2014.9-130824

AVG
Crypt2
2014.0.3538

Bitdefender
Trojan.GenericKD.1206017
1.0.20.1180

Comodo Security
UnclassifiedMalware
16850

Dr.Web
BackDoor.Bulknet.1105
9.0.1.0330

Emsisoft Anti-Malware
Trojan.GenericKD.1206017
8.13.08.24.01

ESET NOD32
Win32/Kryptik.BINY (variant)
7.8744

Fortinet FortiGate
W32/Pushdo.QVP!tr.bdr
8/24/2013

F-Secure
Trojan.GenericKD.1206017
11.2013-26-11_3

G Data
Trojan.GenericKD.1206017
13.8.22

IKARUS anti.virus
Trojan.Crypt2
t3scan.2.0.127

K7 AntiVirus
Riskware
13.170.9438

Kaspersky
Backdoor.Win32.Pushdo
14.0.0.3768

Malwarebytes
Trojan.Zbot
v2013.08.24.01

McAfee
PWSZbot-FDQ!51BB5298E292
5600.7176

Microsoft Security Essentials
TrojanDownloader:Win32/Cutwail
1.163.1557.0

MicroWorld eScan
Trojan.GenericKD.1206017
14.0.0.708

Norman
Troj_Generic.OLDGN
11.20131126

Panda Antivirus
Generic Malware
13.08.24.01

Reason Heuristics
Unnamed.Threat.73
14.3.1.0

Sophos
Mal/Generic-S
4.91

Trend Micro House Call
TROJ_GEN.R0CBB01HT13
7.2.330

Trend Micro
TROJ_SPNR.1AHT13
10.465.26

VIPRE Antivirus
Trojan.Win32.Generic
21014

File size:
57 KB (58,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dot__57.exe

File PE Metadata
Compilation timestamp:
8/22/2013 5:20:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:YAx//J/Hlc4ZfWF13ltiryrqFE5P1kxL4NFs71gchBWTQ8a:jPlcZFUrTENdNFs71gZTh

Entry address:
0x1120

Entry point:
55, 8B, EC, 83, EC, 74, 53, 56, 57, 50, 64, A1, 30, 00, 00, 00, 89, 45, E4, 58, 8B, 45, E4, 8B, 40, 0C, 8B, 40, 0C, 8B, 00, 8B, 08, 8B, 40, 18, 8B, 71, 18, 89, 45, D4, EB, 0A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 33, DB, 53, 53, 53, 68, 38, 10, 35, 00, FF, 15, 10, 10, 35, 00, 53, 68, 41, 01, 00, 00, 8B, F8, 6A, 02, 57, FF, 15, 0C, 10, 35, 00, 8D, 45, C0, 50, 57, FF, 15, 08, 10, 35, 00, 8D, 45, A0, 50, FF, 15, 30, 10, 35, 00, 8B, 45, C0, 83, C0, FE, 74, 19, 6A, 04, FF, 75, C8, FF, 15, 28, 10, 35, 00, FF...
 
[+]

Entropy:
6.1511

Developed / compiled with:
Microsoft Visual C++

Code size:
2 KB (2,048 bytes)

The file dot__57.exe has been seen being distributed by the following URL.

Remove dot__57.exe - Powered by Reason Core Security