eswodee.exe

Hub Client P2P

Interner Community Hub

The executable eswodee.exe, “Internt Commiunity Hub Client” has been detected as malware by 37 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Interner Community Hub

Product:
Hub Client P2P

Description:
Internt Commiunity Hub Client

Version:
1.0.0.2

MD5:
3332084fac3a07b3d186c808da9103b9

SHA-1:
6913a5eb995fdda0f91bf2f8fe569ba4371c553b

SHA-256:
d65bf84a620e8e063885cbb1fbd4c929ea94b1f50bb3d11c25ebffb5874fafa9

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
4/25/2024 10:24:47 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.Cridex.1
5692171

Agnitum Outpost
Trojan.Gimemo
7.1.1

AhnLab V3 Security
Dropper/Win32.Necurs
2015.11.27

Avira AntiVirus
TR/Spy.ZBot.yahd
8.3.2.4

Arcabit
Trojan.Cridex.1
1.0.0.624

avast!
Win32:Ransom-ATD [Trj]
151004-0

AVG
SHeur4
2016.0.2913

Bitdefender
Gen:Heur.Cridex.1
1.0.20.1650

Bkav FE
HW32.Packed
1.3.0.7383

Clam AntiVirus
Win.Trojan.Agent-737936
0.98/21100

Comodo Security
TrojWare.Win32.Spy.Zbot.ABA
23662

Dr.Web
Trojan.Siggen6.15132
9.0.1.05190

Emsisoft Anti-Malware
Gen:Heur.Cridex
10.0.0.5366

ESET NOD32
Win32/Kryptik.CCHX trojan
7.0.302.0

Fortinet FortiGate
W32/Kryptik.CK!tr
11/26/2015

F-Prot
W32/A-ee5b5509
v6.4.7.1.166

F-Secure
Gen:Heur.Cridex.1
5.15.21

G Data
Gen:Heur.Cridex
15.11.25

IKARUS anti.virus
Virus.Win32.Obfuscator
t3scan.1.9.5.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.1061

Malwarebytes
Spyware.Zbot.ED
v2015.11.26.07

McAfee
Trojan.PWS-FBNU!3332084FAC3A
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.211.916.0

MicroWorld eScan
Gen:Heur.Cridex.1
16.0.0.990

NANO AntiVirus
Trojan.Win32.Gimemo.cytrvk
0.30.26.4751

Norman
Gen:Heur.Cridex.1
07.10.2015 03:16:12

nProtect
Trojan/W32.Gimemo.311296.D
15.11.26.01

Panda Antivirus
Trj/Genetic.gen
15.11.26.07

Qihoo 360 Security
QVM19.1.Malware.Gen
1.0.0.1077

Quick Heal
TrojanPWS.Zbot.A7
11.15.14.00

Sophos
Virus 'Troj/Zbot-IMR'
5.15

SUPERAntiSpyware
Trojan.Agent/Gen-Gimemo
9483

Total Defense
Win32/Tnega.QFVEfQC
37.1.62.1

Trend Micro House Call
TROJ_GIMEMO.SM
7.2.330

Trend Micro
TROJ_GIMEMO.SM
10.465.26

Vba32 AntiVirus
Hoax.Gimemo
3.12.26.4

VIPRE Antivirus
Threat.4150696
45208

File size:
304 KB (311,296 bytes)

Product version:
1.0.0.2

Copyright:
Copyright (C) 2014

Original file name:
Hub.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\fuynusep\eswodee.exe

File PE Metadata
Compilation timestamp:
5/20/2014 5:20:18 AM

OS version:
32.32

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
18.0

CTPH (ssdeep):
6144:y/07qhTtqHvsZb+X+ZqsPVC9u2au7n0DINygKFBpetx6rLOIF:y/ttqHvu6X+ZqQGu2au6ItKyx03

Entry address:
0x7F36

Entry point:
55, 8B, EC, 81, EC, 4C, 04, 00, 00, 53, 56, 57, 68, 70, D9, 40, 00, FF, 15, 68, B5, 40, 00, BE, 00, 00, 30, 00, 68, 74, D9, 40, 00, 8D, 85, B4, FB, FF, FF, 50, FF, 15, 24, B5, 40, 00, 4E, 75, EB, 8A, 0D, A8, DA, 40, 00, B8, F7, 2A, 00, 00, D3, E0, 33, D2, B9, 50, 23, 00, 00, F7, F1, B8, 26, F1, B8, 91, C1, EA, 08, 2B, C2, 50, E8, B3, 29, 00, 00, C7, 45, D4, 0E, 03, 00, 00, B8, 06, 0A, 00, 00, 66, 89, 45, E4, B8, C7, 3A, 00, 00, 66, 89, 45, F4, 66, 8B, 45, F4, 0F, B7, C0, C1, E8, 07, 99, B9, DC, 2C, 00, 00...
 
[+]

Entropy:
7.7272

Developed / compiled with:
Microsoft Visual C++

Code size:
76.5 KB (78,336 bytes)

Scheduled Task
Task name:
Security Center Update - 1932414123

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove eswodee.exe - Powered by Reason Core Security