epicbot.exe

The executable epicbot.exe has been detected as malware by 30 anti-virus scanners. This is a setup program which is used to install the application.
Version:
1.0.0.0

MD5:
a15b8b5747e48929de29bd1fc00bdf5d

SHA-1:
08bac699d9e39361041658556a37caa75944f8b3

SHA-256:
ab144e15d5e53c546cc500693ec44cd980e47b4814495d3296e6cc57066a6a4d

Scanner detections:
30 / 68

Status:
Malware

Analysis date:
4/19/2024 9:03:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Delf.135
560

AhnLab V3 Security
Backdoor/Win32.DarkKomet
2015.04.20

Avira AntiVirus
DR/Delphi.Gen
3.6.1.96

avast!
Win32:Malware-gen
2014.9-150724

AVG
Inject
2016.0.3038

Baidu Antivirus
Trojan.Win32.Obfuscator
4.0.3.15724

Bitdefender
Gen:Variant.Delf.135
1.0.20.1025

Clam AntiVirus
Win.Trojan.Agent-256467
0.98/21511

Comodo Security
TrojWare.Win32.Injector.ACLT
21832

Dr.Web
Win32.HLLW.Autoruner1.33800
9.0.1.0205

Emsisoft Anti-Malware
Gen:Variant.Delf.135
8.15.07.24.08

ESET NOD32
Win32/Injector.ADCV (variant)
9.11500

Fortinet FortiGate
W32/Dropper.ASW!tr
7/24/2015

F-Prot
W32/A-4dae0044
v6.4.7.1.166

F-Secure
Gen:Variant.Delf.135
11.2015-24-07_6

G Data
Gen:Variant.Delf.135
15.7.25

IKARUS anti.virus
Virus.Dropper
t3scan.1.8.9.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1686

Malwarebytes
Trojan.Clicker
v2015.07.24.08

McAfee
Artemis!A15B8B5747E4
5600.6694

Microsoft Security Essentials
Worm:Win32/Rebhip.A
1.1.11502.0

MicroWorld eScan
Gen:Variant.Delf.135
16.0.0.615

NANO AntiVirus
Trojan.Win32.Autoruner1.brommk
0.30.16.1110

Norman
Injector.FSDA
11.20150724

Panda Antivirus
Trj/Genetic.gen
15.07.24.08

Qihoo 360 Security
HEUR/Malware.QVM05.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.12.11.0

Sophos
Mal/Generic-S
4.98

Vba32 AntiVirus
TrojanDropper.Injector
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39512

File size:
709.5 KB (726,528 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:c+kol7GdcQhjK+N2nrb9TFBuBQJVh286S9lp5Lzy5KSanCCtiukCZwkNcije710M:c+9l7Gd7XN2nrb9T/uWTvjbaanDkSKi0

Entry address:
0xA59C

Entry point:
55, 8B, EC, B9, 19, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, B8, 2C, A5, 40, 00, E8, C2, AB, FF, FF, 33, C0, 55, 68, F1, AF, 40, 00, 64, FF, 30, 64, 89, 20, B8, 60, DA, 40, 00, BA, 08, B0, 40, 00, E8, 35, 97, FF, FF, 8D, 45, EC, 50, B9, 38, B0, 40, 00, BA, 48, B0, 40, 00, A1, 60, DA, 40, 00, E8, 9D, FB, FF, FF, 8B, 55, EC, B8, 60, DA, 40, 00, E8, 10, 97, FF, FF, B8, 6C, D8, 40, 00, BA, 58, B0, 40, 00, E8, 01, 97, FF, FF, B8, 6C, DA, 40, 00, BA, 68, B0, 40, 00, E8, F2, 96, FF, FF, B8, 68, DA, 40, 00, BA...
 
[+]

Entropy:
7.9627

Developed / compiled with:
Microsoft Visual C++

Code size:
41.5 KB (42,496 bytes)

The file epicbot.exe has been seen being distributed by the following URL.

Remove epicbot.exe - Powered by Reason Core Security