horizonmedia.exe

The executable horizonmedia.exe has been detected as malware by 33 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
df5df24641704866b675e821432cc167

SHA-1:
21f9333fd0c95388021084b21dd3373ecaf4eef3

SHA-256:
bcccb5c901ce9ee53434d3360f8b3ecc0567ec2ea76199b95df22b1fb7eaa39d

Scanner detections:
33 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 10:34:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.X
856

Agnitum Outpost
Win32.Ramnit.Gen.4
7.1.1

AhnLab V3 Security
Win32/Ramnit.R
2014.10.02

Avira AntiVirus
TR/Drop.Agent.pera.1
7.11.30.172

avast!
Win32:Ramnit-AC [Drp]
140929-0

AVG
Win32/Zbot
2014.0.4025

Bitdefender
Win32.Ramnit.X
1.0.20.1375

Clam AntiVirus
W32.Virus.Ramnit-2
0.98/19465

Comodo Security
Virus.Win32.Ramnit.E
19681

Dr.Web
Trojan.Rmnet.1
9.0.1.05190

Emsisoft Anti-Malware
Win32.Ramnit.X
14.10.02

ESET NOD32
Win32/Ramnit.R virus
7.0.302.0

Fortinet FortiGate
W32/Ramnit.R
10/2/2014

F-Prot
W32/Ramnit.P
4.6.5.141

F-Secure
Win32.Ramnit.X
11.2014-02-10_5

G Data
Win32.Ramnit
14.10.24

IKARUS anti.virus
Trojan.Win32.Lebag
t3scan.1.7.8.0

Kaspersky
Virus.Win32.Nimnul
15.0.0.494

McAfee
W32/Ramnit.h
5600.6990

Microsoft Security Essentials
Threat.Undefined
1.185.1828.0

MicroWorld eScan
Win32.Ramnit.X
15.0.0.825

NANO AntiVirus
Virus.Win32.Nimnul.lqdyp
0.28.2.62440

Norman
Packed_Etraps.A
11.20141002

nProtect
Win32.Ramnit.X
14.10.02.01

Quick Heal
W32.Nimnul.E
10.14.14.00

Rising Antivirus
PE:Win32.Nimnul.b!1075353408
23.00.65.14930

Sophos
W32/Ramnit-AY
4.98

Total Defense
Win32/Ramnit.C
37.0.11209

Trend Micro House Call
PE_RAMNIT.HL
7.2.275

Trend Micro
PE_RAMNIT.HL
10.465.02

Vba32 AntiVirus
Virus.Nimnul.E
3.12.26.3

VIPRE Antivirus
Threat.4752940
33520

ViRobot
Win32.Ramnit.D
2011.4.7.4223

File size:
6.7 MB (7,000,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\horizonwimba\jsecuredoor\horizonmedia_2.3.1\data\horizonmedia.exe

File PE Metadata
Compilation timestamp:
3/4/2010 9:17:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
98304:89Em18BRO/LRaenosD5OKUVksgnMO7makF4:8l8uNnrd/sgMOCvF4

Entry address:
0x48EC46

Entry point:
60, BE, 46, EC, 88, 00, B9, 60, C5, 4C, 01, BB, B6, 58, 90, 00, 8D, 15, 70, 04, 00, 00, 89, F5, EB, 44, 83, E2, F0, 31, C9, 31, C0, 31, F6, 51, B9, 10, 00, 00, 00, 0F, B6, 84, 0D, EE, 04, 00, 00, 8A, 04, 03, 88, 84, 0D, DE, 04, 00, 00, E2, EC, B9, 10, 00, 00, 00, 8A, 84, 0D, DE, 04, 00, 00, 88, 44, 0F, FF, E2, F3, 59, 83, C3, 10, 83, C7, 10, 83, C1, 10, 39, D1, 75, C6, C3, 56, 51, 53, 8D, 99, 70, FB, FF, FF, 8D, 7D, 6F, E8, AB, FF, FF, FF, 25, DC, 64, 90, 00, FF, 25, E0, 64, 90, 00, FF, 25, E4, 64, 90, 00...
 
[+]

Entropy:
6.6354

Code size:
5 MB (5,263,360 bytes)

Remove horizonmedia.exe - Powered by Reason Core Security