tmp5435fce8.exe

The executable tmp5435fce8.exe has been detected as malware by 26 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
d4f046d012efcc20901f2fea5a7c5248

SHA-1:
6e3409fcff7ee0c0d9ef1abf5568b354b6e04add

SHA-256:
8c9a17b8d9bf74568ab1890eae492eb15ad92b3506d527591fac0c95d0b0379f

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
5/2/2024 10:00:15 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Worm/Win32.Ngrbot
2012.05.12

Avira AntiVirus
TR/Dropper.Gen
7.11.29.202

avast!
Win32:VBCrypt-GT [Trj]
2014.9-170315

AVG
PSW.Generic9
2018.0.2438

Bitdefender
Trojan.Generic.7344635
1.0.20.370

Clam AntiVirus
Trojan.Zbot-20022
0.98/18155

Comodo Security
TrojWare.Win32.Trojan.Agent.Gen
12294

Dr.Web
Trojan.VbCrypt.66
9.0.1.074

Emsisoft Anti-Malware
Trojan-Dropper.Win32.VB!IK
8.17.03.15.10

ESET NOD32
Win32/Injector.OCI (variant)
11.7130

Fortinet FortiGate
W32/VBInjector.W!tr
3/15/2017

F-Secure
Trojan.Generic.7344635
11.2017-15-03_4

G Data
Trojan.Generic.7344635
17.3.22

IKARUS anti.virus
Trojan-Dropper.Win32.VB
t3scan.1.1.118.0

K7 AntiVirus
Spyware
13.138.6854

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.-1315

McAfee
PWS-Zbot.gen.oz
5600.6094

Microsoft Security Essentials
Trojan:Win32/Coremhead
1.163.1557.0

Norman
W32/Troj_Generic.IYFE
11.20170315

nProtect
Trojan.Generic.7344635
12.05.11.02

Panda Antivirus
Generic Trojan
17.03.15.10

Quick Heal
TrojanSpy.Zbot.dcjb
3.17.12.00

Sophos
Troj/VB-FVY
4.73 TP

Trend Micro House Call
TROJ_GEN.RC1C1AD
7.2.74

Trend Micro
TROJ_GEN.RC1C1AD
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
11904

File size:
208.5 KB (213,504 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/21/2011 2:47:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1674

Entry point:
68, 20, 18, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 6C, 65, 00, 00, 00, 00, 00, 06, 00, 00, 00, E8, 34, 40, 00, 07, 00, 00, 00, 98, 32, 40, 00, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 6C, 65, 73, 46, 6C, 6F, 72, 61, 6C, 65, 73, 07, 00, 00, 00, 34, 31, 40, 00...
 
[+]

Code size:
56 KB (57,344 bytes)

Remove tmp5435fce8.exe - Powered by Reason Core Security