kyilimb.exe

The executable kyilimb.exe has been detected as malware by 29 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
5600a192a47400205628a05bf6f5a043

SHA-1:
a82cebcd1aad6704cadc57882685d27364ac8a92

SHA-256:
cf924d96c4f0e7b7568e1ca1a4af0232d9d06aafeb7ff4f8ea788e28f7188eeb

Scanner detections:
29 / 68

Status:
Malware

Analysis date:
5/8/2024 4:20:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Agent.BGHP
827

Agnitum Outpost
Trojan.Kryptik
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2014.10.31

Avira AntiVirus
TR/Spy.ZBot.excrt
7.11.183.62

avast!
Win32:Trojan-gen
141025-0

AVG
Inject2
2015.0.3305

Bitdefender
Trojan.Agent.BGHP
1.0.20.1515

Bkav FE
HW32.Packed
1.3.0.6185

Clam AntiVirus
Win.Trojan.Agent-808876
0.98/19586

Comodo Security
TrojWare.Win32.PWS.Zbot.COS
19997

Dr.Web
Trojan.Siggen6.22973
9.0.1.0313

Emsisoft Anti-Malware
Trojan.Agent.BGHP
8.14.10.30.07

ESET NOD32
Win32/Kryptik.COSX (variant)
8.10646

Fortinet FortiGate
W32/Yakes.GAKM!tr
10/30/2014

F-Prot
W32/A-bd3b3b34
v6.4.7.1.166

F-Secure
Trojan.Agent.BGHP
11.2014-30-10_5

G Data
Trojan.Agent.BGHP
14.10.24

K7 AntiVirus
Trojan
13.185.13853

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3021

Malwarebytes
Spyware.Zbot.ED
v2014.10.30.07

McAfee
PWSZbot-FAFF!5600A192A474
5600.6961

Microsoft Security Essentials
PWS:Win32/Zbot
1.11104

NANO AntiVirus
Trojan.Win32.Siggen6.dhzcgl
0.28.6.62995

nProtect
Trojan.Agent.BGHP
14.11.05.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.9.16

Sophos
Troj/Wonton-JF
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
10248

Total Defense
Win32/Zbot.PJXLRd
37.0.11264

VIPRE Antivirus
Threat.4439742
34232

File size:
286.8 KB (293,689 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\fuoqryu\kyilimb.exe

File PE Metadata
Compilation timestamp:
7/8/1996 1:00:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:zp7+L3yGB9GXDC/g//9QpgFQhtrTAwjDuQdOeEqUE+GKcEZVRIHK5qRg1:t7+L+DC/g//KpIQht7vuQdfExdwHK5qy

Entry address:
0x9BDA

Entry point:
55, 8B, EC, 6A, FF, 68, 98, BC, 40, 00, 68, D0, 9D, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, EC, A1, 40, 00, 59, 83, 0D, FC, C1, 51, 00, FF, 83, 0D, 00, C2, 51, 00, FF, FF, 15, E8, A1, 40, 00, 8B, 0D, F8, C1, 51, 00, 89, 08, FF, 15, E4, A1, 40, 00, 8B, 0D, F4, C1, 51, 00, 89, 08, A1, E0, A1, 40, 00, 8B, 00, A3, 04, C2, 51, 00, E8, 28, 01, 00, 00, 39, 1D, DC, D1, 40, 00, 75, 0C, 68, 6E, 9D, 40, 00, FF, 15, DC, A1...
 
[+]

Entropy:
7.7391

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
36 KB (36,864 bytes)

Scheduled Task
Task name:
Security Center Update - 2231766517

Trigger:
Daily (Runs daily at 10:00 AM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove kyilimb.exe - Powered by Reason Core Security