sbtt.exe

The executable sbtt.exe has been detected as malware by 7 anti-virus scanners. While running, it connects to the Internet address 195.34.13.149.zylom.net on port 443.
MD5:
041f901f0d1d5525c43b0521ff420ccb

SHA-1:
02c64297df7356f5f4520e12086f3bbeab962cf4

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 7:23:35 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-141128

Bkav FE
HW32.Packed
1.3.0.4959

Dr.Web
Trojan.Inject1.12926
9.0.1.0332

G Data
Win32.Trojan.Agent.M7X2YV
14.11.24

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141126

Trend Micro House Call
PAK_Generic.009
7.2.332

Trend Micro
PAK_Generic.009
10.465.28

File size:
1.6 MB (1,676,289 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\spongebob squarepants obstacle odyssey 2\sbtt.exe

File PE Metadata
Compilation timestamp:
3/16/2006 3:15:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:wOHSzk5rBX8AxW9i9koDax2/+9VGU7RGMXrubjIglW/aIaJfeolUBRbYmZLT:w+SzkVt899xCaAUUMybflW29lWR9ZLT

Entry address:
0x5AB09A

Entry point:
89, 25, 04, 60, 5C, 10, 68, C5, B0, 5A, 10, 64, FF, 35, 00, 00, 00, 00, 71, 05, 89, DB, 70, 01, 80, 64, 89, 25, 00, 00, 00, 00, EB, 01, BD, E9, 66, 08, 00, 00, EB, 01, BB, 55, 89, E5, EB, 02, 69, B1, EB, 03, E4, E0, A7, EB, 03, 30, DB, A0, EB, 01, B9, 7C, 06, 90, 7C, 06, 7D, 04, F2, EB, F9, BA, 8B, 45, 08, EB, 03, 81, C4, 73, EB, 02, 80, C7, 8B, 00, 3D, 03, 00, 00, 80, EB, 03, 3B, EB, 07, EB, 02, E8, 56, EB, F8, 00, EB, 02, 23, 04, EB, 02, 38, AE, 75, 04, 31, C0, EB, 24, 3D, 04, 00, 00, 80, 75, 14, EB, 02...
 
[+]

Entropy:
7.9285  (probably packed)

Code size:
1 MB (1,056,768 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to 195.34.13.149.zylom.net  (149.13.34.195:443)

Remove sbtt.exe - Powered by Reason Core Security