gihozu.exe

Ensiem Corporatu

The executable gihozu.exe, “Ensiem Visatl Studie 2020” has been detected as malware by 24 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Ensiem Corporatu

Description:
Ensiem Visatl Studie 2020

Version:
13.5.30229.52188

MD5:
718ec9a8233680ffaeb1d61ed1b5742d

SHA-1:
359f4b67b19253b29a4fa63b0cca25879fbaac65

SHA-256:
4d6a1136c52dcd91857608c38f91d0d5ea48061f796c40b5a10854deff5eeaf6

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/19/2024 5:27:01 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.12358354
6204532

AhnLab V3 Security
Trojan/Win32.Necurs
2014.12.20

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.30.172

avast!
Win32:Malware-gen
141214-1

AVG
Zbot
2015.0.3255

Bitdefender
Trojan.Generic.12358354
1.0.20.1770

Dr.Web
Trojan.PWS.Panda.7719
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.12358354
9.0.0.4668

ESET NOD32
Win32/Spy.Zbot.ABA
8.10907

Fortinet FortiGate
W32/Zbot.ABA!tr
12/20/2014

F-Secure
Trojan.Generic.12358354
5.13.68

G Data
Trojan.Generic.12358354
14.12.24

Kaspersky
Trojan-Spy.Win32.Zbot
15.0.0.543

Malwarebytes
Trojan.Zemot
v2014.12.20.08

McAfee
Trojan.MysticCompressor!718EC9A82336
16.8.708.2

Microsoft Security Essentials
Threat.Undefined
1.191.419.0

MicroWorld eScan
Trojan.Generic.12358354
15.0.0.1062

NANO AntiVirus
Trojan.Win32.Panda.dkomso
0.28.6.64267

Norman
Trojan.Generic.12358354
04.12.2014 14:30:06

nProtect
Trojan.Generic.12358354
14.12.19.01

Panda Antivirus
Trj/Genetic.gen
14.12.20.08

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.23

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
10166

VIPRE Antivirus
Threat.4150696
35418

File size:
499.6 KB (511,582 bytes)

Product version:
13.5.30229.52188

Original file name:
baesh.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\idxuyl\gihozu.exe

File PE Metadata
Compilation timestamp:
7/11/2012 5:29:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Yh8u0eF19AkKSSsuJBCfGLHKI1Vuz1eWq:Yh8uF/JXuPPns4Wq

Entry address:
0x5F54

Entry point:
55, 8B, EC, 81, EC, D8, 00, 00, 00, B8, 42, 00, 00, 00, 89, 45, D0, 53, 8B, 5D, D0, 89, 5D, D0, 56, 89, 45, D0, 57, BA, D6, 97, 00, 00, 23, D0, 89, 55, D0, 33, C3, 89, 45, AC, 68, 68, 00, 41, 00, FF, 15, 20, A1, 40, 00, 0B, D8, 8B, 35, 38, 00, 41, 00, 83, FB, 46, 75, 0D, 03, DB, 83, FB, 68, 74, 06, 83, CB, 42, 89, 5D, AC, 89, 75, AC, 89, 45, 94, 89, 45, AC, 8D, 7D, D8, 57, FF, 15, F4, A0, 40, 00, 8B, 5D, AC, 83, EB, 76, 83, FB, 20, 74, 40, 8B, C6, 83, E8, EE, 89, 7D, D0, 83, FB, A7, 74, 33, 81, FB, 19, DD...
 
[+]

Entropy:
6.4753

Developed / compiled with:
Microsoft Visual C++

Code size:
33 KB (33,792 bytes)

Scheduled Task
Task name:
Security Center Update - 2488632029

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove gihozu.exe - Powered by Reason Core Security