msi25011.exe

The executable msi25011.exe has been detected as malware by 38 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
495ff920a3b2166cea38030f547efeaf

SHA-1:
84b0ef05086c0f36dd0c041b0d9aee3e81f10761

SHA-256:
06887219e79308829a48745b7709b84b6e969696ef15503b36e4f26bf0ce353b

Scanner detections:
38 / 68

Status:
Malware

Analysis date:
5/7/2024 6:53:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1604583
835

AhnLab V3 Security
Trojan/Win32.Agent
14.10.22

Avira AntiVirus
TR/ATRAPS.Gen
7.11.148.252

avast!
Win32:Malware-gen
2014.9-141022

AVG
PSW.Generic12
2015.0.3313

Baidu Antivirus
Trojan.Win32.Zbot
4.0.3.141022

Bitdefender
Trojan.GenericKD.1604583
1.0.20.1475

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
UnclassifiedMalware
18257

Dr.Web
Trojan.PWS.Panda.5676
9.0.1.0295

Emsisoft Anti-Malware
Trojan.GenericKD.1604583
8.14.10.22.06

ESET NOD32
Win32/Kryptik.BZJW (variant)
8.9786

Fortinet FortiGate
W32/Cridex.BQRO!tr
10/22/2014

F-Secure
Trojan.GenericKD.1604583
11.2014-22-10_4

G Data
Trojan.GenericKD.1604583
14.10.24

IKARUS anti.virus
Trojan-PWS.Win32.Zbot
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.177.12041

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3061

Malwarebytes
Trojan.Zbot
v2014.10.22.06

McAfee
RDN/Generic PWS.y!yw
5600.6969

Microsoft Security Essentials
PWS:Win32/Zbot.GOV
1.10502

MicroWorld eScan
Trojan.GenericKD.1604583
15.0.0.885

NANO AntiVirus
Trojan.Win32.Kryptik.cvbdcg
0.28.0.59608

Norman
Troj_Generic.SZQJN
11.20141022

nProtect
Trojan-Spy/W32.ZBot.518656.AA
14.05.11.01

Panda Antivirus
Generic Malware
14.10.22.06

Qihoo 360 Security
HEUR/Malware.QVM07.Gen
1.0.0.1015

Quick Heal
Trojan.PWSZbot.GO4
10.14.14.00

Sophos
Mal/Cridex-F
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zusy
10283

Total Defense
Win32/Zbot.ILLYQe
37.0.10931

Trend Micro House Call
TSPY_ZBOT.ADXN
7.2.295

Trend Micro
TSPY_ZBOT.ADXN
10.465.22

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29106

ViRobot
Trojan.Win32.S.Agent.518656.C
2011.4.7.4223

XVirus List
Win32.Detected
2.10.22

Zillya! Antivirus
Trojan.Zbot.Win32.150154
2.0.0.1785

File size:
506.5 KB (518,656 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\msi25011.exe

File PE Metadata
Compilation timestamp:
1/7/2014 9:25:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:LLCkdJ41K6QIaGwhrhJ+U8BHA5aHuMfiJti0KDJiHxBARXv8bWkrn7l9iPgknH5:LWzfQNlzOHP5fAU0kpoyt5

Entry address:
0x1797

Entry point:
55, 8B, EC, 6A, FF, 68, 58, F5, 40, 00, 68, 17, 19, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 4C, E1, 40, 00, 59, 83, 0D, 74, F5, 40, 00, FF, 83, 0D, 78, F5, 40, 00, FF, FF, 15, 70, E1, 40, 00, 8B, 0D, 70, F5, 40, 00, 89, 08, FF, 15, 3C, E1, 40, 00, 8B, 0D, 6C, F5, 40, 00, 89, 08, A1, 60, E1, 40, 00, 8B, 00, A3, 7C, F5, 40, 00, E8, 10, 01, 00, 00, 39, 1D, 60, F5, 40, 00, 75, 0C, 68, 13, 19, 40, 00, FF, 15, 18, E1...
 
[+]

Entropy:
5.2697

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
2.5 KB (2,560 bytes)

Remove msi25011.exe - Powered by Reason Core Security