fuopal.exe

The executable fuopal.exe has been detected as malware by 25 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
a92393303bc72ba2e722bc797b256882

SHA-1:
ccbc66c9a73a719f5c527a3d01679f602f6518f0

SHA-256:
5f0fb87e7575236a1557e892ced89a496757d38d083ed12c46f75c237f32fd84

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/26/2024 11:36:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.458740
865

AhnLab V3 Security
Dropper/Win32.Necurs
2014.09.23

Avira AntiVirus
TR/Crypt.ZPACK.93674
7.11.173.208

avast!
Win32:Dropper-gen [Drp]
140908-2

AVG
Crypt3
2015.0.3343

Bitdefender
Gen:Variant.Kazy.458740
1.0.20.1325

Bkav FE
HW32.Paked
1.3.0.4959

Dr.Web
Trojan.Siggen6.15132
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.458740
8.14.09.22.01

ESET NOD32
Win32/Kryptik.CLQO (variant)
8.10448

Fortinet FortiGate
W32/Kryptik.VCZV!tr
9/22/2014

F-Secure
Gen:Variant.Kazy.458740
11.2014-22-09_2

G Data
Gen:Variant.Kazy.458740
14.9.24

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.1.7.8.0

K7 AntiVirus
Backdoor
13.183.13451

Kaspersky
Packed.Win32.Katusha
15.0.0.494

McAfee
PWSZbot-FADO!A92393303BC7
5600.6999

Microsoft Security Essentials
PWS:Win32/Zbot
1.11005

MicroWorld eScan
Gen:Variant.Kazy.458740
15.0.0.795

NANO AntiVirus
Trojan.Win32.Katusha.dfiavv
0.28.2.62286

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14920

Sophos
Mal/EncPk-AFC
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Kryptik
10344

VIPRE Antivirus
Threat.4150696
32938

File size:
285.6 KB (292,461 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\usinmio\fuopal.exe

File PE Metadata
Compilation timestamp:
3/15/2012 10:06:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:iIs3PT9gBnEaRPXVyEaSqB7TS9/IAcY6T2ii0eZWmdpH:O/T9MEuzaR7eKA6i0cx

Entry address:
0x12964

Entry point:
55, 8B, EC, 81, EC, 18, 01, 00, 00, 8B, 15, 0C, 38, 43, 00, 81, F2, 00, 13, 16, 08, 89, 55, B4, 53, B8, 3F, 72, 00, 00, 89, 55, B4, 89, 45, B4, 56, 89, 55, B4, 57, 03, D0, 8B, 4D, B4, 89, 4D, B4, 83, F9, 9F, 74, 03, 89, 4D, B4, 89, 4D, B4, 89, 95, 40, FF, FF, FF, 33, C1, 8B, F2, EB, 13, 33, DA, 3B, 9D, 6C, FF, FF, FF, 74, 09, 83, C3, EE, 89, 9D, E8, FE, FF, FF, 8D, 85, 38, FF, FF, FF, 50, FF, 15, 7C, A8, 42, 00, 8B, 4D, B4, F7, C1, AB, 00, 00, 00, 75, 0E, 3B, 0D, 38, 38, 43, 00, 74, 06, 83, C1, 96, 89, 4D...
 
[+]

Entropy:
7.8731

Developed / compiled with:
Microsoft Visual C++

Code size:
164 KB (167,936 bytes)

Scheduled Task
Task name:
Security Center Update - 4134347779

Trigger:
Daily (Runs daily at 1:00)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove fuopal.exe - Powered by Reason Core Security