tmp6a27.exe

ISCT Driver

The executable tmp6a27.exe, “ISCT and IFFS Driver” has been detected as malware by 24 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Product:
ISCT Driver

Description:
ISCT and IFFS Driver

Version:
1, 0, 0, 1002

MD5:
b85de75ec65a33686b789ee71360fe59

SHA-1:
56671bdc1e49d635e13394a2de35a85c710ff046

SHA-256:
c4d4b4d3d36ff24f22e306014bce63889c24054f510893509d0c88e97621bf43

Scanner detections:
24 / 68

Status:
Malware

Analysis date:
4/25/2024 3:07:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.501077
799

AhnLab V3 Security
Trojan/Win32.Necurs
2014.11.28

Avira AntiVirus
TR/Spy.ZBot.ulpoi
7.11.189.70

avast!
Win32:GenMalicious-AQG [Trj]
141119-1

AVG
Crypt3
2015.0.3277

Baidu Antivirus
Trojan.Win32.Zbot
4.0.3.141128

Bitdefender
Gen:Variant.Kazy.501077
1.0.20.1660

Bkav FE
W32.ATVC_OnsurotLTL.Trojan
1.3.0.6267

Dr.Web
Trojan.DownLoad3.35002
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.501077
9.0.0.4570

ESET NOD32
Win32/Injector.BQCI trojan
7.0.302.0

Fortinet FortiGate
W32/Injector.BPOZ!tr
11/28/2014

F-Secure
Gen:Variant.Kazy.501077
11.2014-28-11_6

G Data
Gen:Variant.Kazy.501077
14.11.24

Kaspersky
Trojan-Spy.Win32.Zbot
15.0.0.543

Malwarebytes
Trojan.Pseudo.isct
v2014.11.28.01

Microsoft Security Essentials
Threat.Undefined
1.189.840.0

MicroWorld eScan
Gen:Variant.Kazy.501077
15.0.0.996

Norman
Rovnix.DT
11.20141128

nProtect
Trojan-Spy/W32.ZBot.345646
14.11.27.01

Panda Antivirus
Trj/CI.A
14.11.28.01

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.141126

VIPRE Antivirus
Threat.4150696
35088

File size:
337.5 KB (345,646 bytes)

Product version:
1, 0, 0, 1002

Copyright:
Copyright (C) 2011

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\microsoft\secure\icons\temp\tmp6a27.exe

File PE Metadata
OS version:
2.514

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
1.1

CTPH (ssdeep):
6144:z9OfPmeND7Va+/uE9T2u8LAdu4uu0dIgPjWteYEbnkZMd:Z2PmA5a+/uA2u8AngPieYEbkZMd

Entry address:
0xBCD5

Entry point:
55, 8B, EC, 90, 90, 68, 4C, 9C, 90, 00, 68, C4, EF, 40, 00, 64, A1, 00, 00, 00, 00, 90, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, 90, 15, A4, 99, 43, 00, 33, D2, 8A, D4, 89, 15, 98, 6B, 43, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 94, 6B, 43, 00, C1, E1, 08, 03, CA, 89, 0D, 90, 6B, 43, 00, C1, E8, 10, A3, 8C, 6B, 43, 00, 6A, 01, E8, 29, 32, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C2, 00, 00, 00, 59, E8, 34, 2F, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B1, 00, 90, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.6257

Developed / compiled with:
Microsoft Visual C++

Code size:
16.1 MB (16,932,864 bytes)

Remove tmp6a27.exe - Powered by Reason Core Security