inpahio.exe

Meskisift Visaal Studio 2010

Meskisift Corporatien

The executable inpahio.exe, “Meskisift Visaal Studie 2010” has been detected as malware by 31 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Iznyigs’. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Meskisift Corporatien

Product:
Meskisift® Visaal Studio® 2010

Description:
Meskisift Visaal Studie 2010

Version:
1.9.43074.5121 built by: SP1Rel

MD5:
eba5d2aaf75242081bedf21ce9b11f32

SHA-1:
bd8d72c5e014ede99fb8f4f4b3b3188805b0e4e5

SHA-256:
6d75f7ec905e6a29325a4f090d6005c8f26dddcd34963b04a60357fda4e9a57f

Scanner detections:
31 / 68

Status:
Malware

Analysis date:
4/26/2024 10:48:26 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.435317
889

Agnitum Outpost
Trojan.Blocker
7.1.1

AhnLab V3 Security
Trojan/Win32.ZBot
2014.08.30

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.30.172

avast!
Win32:Zbot-UJX [Trj]
140813-1

AVG
Trojan horse Zbot.MXG
2014.0.4015

Bitdefender
Gen:Variant.Kazy.435317
1.0.20.1210

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
TrojWare.Win32.Injector.BJMY
19358

Emsisoft Anti-Malware
Gen:Variant.Kazy.435317
9.0.0.4324

ESET NOD32
Win32/Kryptik.CJJK (variant)
8.10338

Fortinet FortiGate
W32/Kryptik.CJED!tr
8/30/2014

F-Prot
W32/Ransom.AW.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.435317
11.2014-30-08_7

G Data
Gen:Variant.Kazy.435317
14.8.24

IKARUS anti.virus
Trojan-Spy.Win32.Zbot
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13198

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3330

Malwarebytes
Trojan.Zbot.gen
v2014.08.30.01

McAfee
PWSZbot-FBTA!EBA5D2AAF752
5600.7023

Microsoft Security Essentials
Threat.Undefined
1.183.900.0

MicroWorld eScan
Gen:Variant.Kazy.435317
15.0.0.726

NANO AntiVirus
Trojan.Win32.Blocker.debhgb
0.28.2.61861

Norman
ZBot.UYZK
11.20140830

Panda Antivirus
Trj/Genetic.gen
14.08.30.01

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14828

Sophos
Mal/Agent-APH
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Falcomp[i]
10391

Total Defense
Win32/Zbot.ECGNdDD
37.0.11151

VIPRE Antivirus
Threat.4789469
32210

Zillya! Antivirus
Trojan.Blocker.Win32.21082
2.0.0.1906

File size:
302.7 KB (309,950 bytes)

Product version:
1.9.43074.5121

Copyright:
© Meskisift Corporatien. All rights reserved.

Original file name:
divanv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\awazuhca\inpahio.exe

File PE Metadata
Compilation timestamp:
6/15/2012 11:25:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:s3zq2+jdadd2Phn2J4ahrR4tVgM9akL3k1:QCg7N4ajGVPLE

Entry address:
0xCA24

Entry point:
55, 8B, EC, 81, EC, B0, 02, 00, 00, B9, 75, 60, 00, 00, 89, 8D, AC, FD, FF, FF, 53, 8B, 95, AC, FD, FF, FF, 89, 95, AC, FD, FF, FF, 56, 33, D1, 3B, 95, 5C, FF, FF, FF, 75, 06, 89, 95, AC, FD, FF, FF, 57, 03, C9, EB, 1B, 33, C6, BB, 42, 00, 00, 00, 89, 85, B8, FE, FF, FF, EB, 0C, 8B, D8, EB, 08, 2B, D9, 89, 9D, 84, FD, FF, FF, 81, FB, 34, 95, 00, 00, 74, 0F, 53, 53, 6A, A4, 6A, BE, 53, E8, 9F, 25, 00, 00, 83, C4, 14, 6A, 62, 6A, 5C, FF, 15, 14, 5E, 42, 00, 3B, C3, 74, 58, BA, D6, 00, 00, 00, 33, D0, 81, FA...
 
[+]

Entropy:
7.8484

Developed / compiled with:
Microsoft Visual C++

Code size:
141 KB (144,384 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Iznyigs

Command:
C:\users\{user}\appdata\roaming\awazuhca\inpahio.exe


Remove inpahio.exe - Powered by Reason Core Security