haxoe.exe

The executable haxoe.exe has been detected as malware by 29 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
636e9733825567d3e8135b3ec9fe9e5a

SHA-1:
5e4c0d3a72c49fa809912b6d84c488f53deec13d

SHA-256:
97077be66452e2256b6dfca34389b40b107da2acca54fee54f7aacb557d839e9

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
4/25/2024 4:58:09 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.BGHP
827

Agnitum Outpost
Trojan.Kryptik
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2014.10.31

Avira AntiVirus
TR/Spy.ZBot.excrt
7.11.183.62

avast!
Win32:Trojan-gen
2014.9-141031

AVG
Inject2
2015.0.3305

Bitdefender
Trojan.Agent.BGHP
1.0.20.1520

Bkav FE
HW32.Packed
1.3.0.6185

Clam AntiVirus
Win.Trojan.Agent-808876
0.98/19586

Comodo Security
TrojWare.Win32.PWS.Zbot.COS
19997

Dr.Web
Trojan.Siggen6.22973
9.0.1.0313

Emsisoft Anti-Malware
Trojan.Agent.BGHP
8.14.10.31.07

ESET NOD32
Win32/Kryptik.COSX (variant)
8.10649

Fortinet FortiGate
W32/Yakes.GAKM!tr
10/31/2014

F-Prot
W32/A-bd3b3b34
v6.4.7.1.166

F-Secure
Trojan.Agent.BGHP
11.2014-31-10_6

G Data
Trojan.Agent.BGHP
14.10.24

K7 AntiVirus
Trojan
13.185.13853

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3018

Malwarebytes
Spyware.Zbot.ED
v2014.10.31.07

McAfee
PWSZbot-FAFF!636E97338255
5600.6961

Microsoft Security Essentials
PWS:Win32/Zbot
1.11104

NANO AntiVirus
Trojan.Win32.Siggen6.dhzcgl
0.28.6.62995

nProtect
Trojan.Agent.BGHP
14.10.31.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.9.16

Sophos
Troj/Wonton-JF
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
10248

Total Defense
Win32/Zbot.PJXLRd
37.0.11264

VIPRE Antivirus
Trojan.Win32.Generic
34392

File size:
286.8 KB (293,689 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\emloobes\haxoe.exe

File PE Metadata
Compilation timestamp:
7/8/1996 6:00:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:zp7+L3yGB9GXDC/g//9QpgFQhtrTAwjDuQdOeEqUE+GKcEZVRIHK5qRgs4:t7+L+DC/g//KpIQht7vuQdfExdwHK5qK

Entry address:
0x9BDA

Entry point:
55, 8B, EC, 6A, FF, 68, 98, BC, 40, 00, 68, D0, 9D, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, EC, A1, 40, 00, 59, 83, 0D, FC, C1, 51, 00, FF, 83, 0D, 00, C2, 51, 00, FF, FF, 15, E8, A1, 40, 00, 8B, 0D, F8, C1, 51, 00, 89, 08, FF, 15, E4, A1, 40, 00, 8B, 0D, F4, C1, 51, 00, 89, 08, A1, E0, A1, 40, 00, 8B, 00, A3, 04, C2, 51, 00, E8, 28, 01, 00, 00, 39, 1D, DC, D1, 40, 00, 75, 0C, 68, 6E, 9D, 40, 00, FF, 15, DC, A1...
 
[+]

Entropy:
7.7392

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
36 KB (36,864 bytes)

Scheduled Task
Task name:
Security Center Update - 2153863635

Trigger:
Daily (Runs daily at 11:00:00)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove haxoe.exe - Powered by Reason Core Security