loader.exe

The executable loader.exe has been detected as malware by 21 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
de3fb45dae91407c40d54f7148a57b35

SHA-1:
88b0d5fbc895e3a254e3aefc1f61c3a1d73779ba

SHA-256:
f4d7c9a5f2842097185e1096695d377da1212193bfcd449870ea621ec5bf0c90

Scanner detections:
21 / 68

Status:
Malware

Analysis date:
4/24/2024 1:52:09 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.166462
896

AhnLab V3 Security
Trojan/Win32.Zbot
2014.08.23

Avira AntiVirus
TR/Proxy.Gen
7.11.30.172

avast!
Sf:Zbot-IE [Trj]
140813-1

AVG
Found Win32/DH{fDATFE8VGwok}
2014.0.4007

Bitdefender
Gen:Variant.Kazy.166462
1.0.20.1170

Dr.Web
Trojan.DownLoader9.18794
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.166462
8.14.08.22.06

F-Secure
Gen:Variant.Kazy.166462
11.2014-22-08_6

G Data
Gen:Variant.Kazy.166462
14.8.24

Kaspersky
HEUR:Trojan.Win32.Invader
14.0.0.3366

Microsoft Security Essentials
Threat.Undefined
1.181.345.0

MicroWorld eScan
Gen:Variant.Kazy.166462
15.0.0.702

NANO AntiVirus
Trojan.Win32.Invader.cstlxn
0.28.2.61721

Panda Antivirus
Trj/Genetic.gen
14.08.22.06

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Sophos
Mal/Behav-010
4.98

Total Defense
Win32/Zbot.CXZ
37.0.11137

Trend Micro House Call
Mal_DLDER
7.2.234

Trend Micro
Mal_DLDER
10.465.22

VIPRE Antivirus
Threat.4797194
32210

File size:
24.5 KB (25,088 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/27/2013 12:53:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:sPYq6T2tN738xNIVxndvPBWTevnYWsB8XRu:71T2tB3nxnd3ZY7B8hu

Entry address:
0x3D7F

Entry point:
6A, 00, E8, FA, FD, FF, FF, 80, 3D, 98, 83, 40, 00, 00, 74, 12, E8, 40, FA, FF, FF, 84, C0, 74, 09, 6A, 00, E8, F1, 02, 00, 00, EB, 2A, E8, 2E, FA, FF, FF, 84, C0, 74, 21, E8, 4A, FB, FF, FF, 84, C0, 74, 18, 56, E8, CB, FC, FF, FF, 8B, F0, 85, F6, 74, 0B, E8, 77, FD, FF, FF, 56, E8, BF, FB, FF, FF, 5E, 6A, 00, FF, 15, 70, 10, 40, 00, CC, 55, 8B, EC, 81, EC, 40, 01, 00, 00, 83, 65, F8, 00, 83, 65, FC, 00, 53, 56, 6A, 26, 8D, 75, D8, 58, E8, EC, F7, FF, FF, 0F, B6, 05, 98, 83, 40, 00, 50, FF, 35, 94, 83, 40...
 
[+]

Entropy:
6.6068

Code size:
16.5 KB (16,896 bytes)

Remove loader.exe - Powered by Reason Core Security