updateflashplayer_0a120c28.exe

Ensiem Corporatu

The executable updateflashplayer_0a120c28.exe, “Ensiem Visatl Studie 2020” has been detected as malware by 27 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Ensiem Corporatu

Description:
Ensiem Visatl Studie 2020

Version:
13.5.30229.52188

MD5:
49572dff7c0bd12330fdf79e5d6c4004

SHA-1:
7ded91d8e633c53146ddb523bd1c3d607edf8ec9

SHA-256:
96c9507a84dc16fab03700fd198d5485d19036f8f371782bb90b4b65dea6ab62

Scanner detections:
27 / 68

Status:
Malware

Analysis date:
4/20/2024 3:27:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.520210
777

AhnLab V3 Security
Trojan/Win32.Necurs
2014.12.18

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.196.138

avast!
Win32:Malware-gen
2014.9-141220

AVG
Zbot
2015.0.3255

Bitdefender
Gen:Variant.Zusy.119346
1.0.20.1770

Dr.Web
Trojan.PWS.Panda.7719
9.0.1.0354

Emsisoft Anti-Malware
Gen:Variant.Kazy.520210
8.14.12.20.08

ESET NOD32
Win32/Spy.Zbot.ABA
8.10896

Fortinet FortiGate
W32/Zbot.ABA!tr.spy
12/20/2014

F-Secure
Gen:Variant.Zusy.119346
11.2014-20-12_7

G Data
Gen:Variant.Zusy.119346
14.12.24

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.8.5.0

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.2768

Malwarebytes
Trojan.Zemot
v2014.12.20.08

McAfee
MysticCompressor!49572DFF7C0B
5600.6911

Microsoft Security Essentials
PWS:Win32/Zbot
1.11302

MicroWorld eScan
Gen:Variant.Kazy.520210
15.0.0.1062

NANO AntiVirus
Trojan.Win32.Panda.dkomso
0.28.6.64267

Norman
Trojan.Generic.12358354
11.20141221

nProtect
Trojan.Generic.12358354
14.12.19.01

Panda Antivirus
Trj/Genetic.gen
14.12.21.11

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.23

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Zbot
10163

Trend Micro House Call
Suspicious_GEN.F47V1218
7.2.354

VIPRE Antivirus
Threat.4150696
35418

File size:
499.6 KB (511,582 bytes)

Product version:
13.5.30229.52188

Original file name:
baesh.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_0a120c28.exe

File PE Metadata
Compilation timestamp:
7/11/2012 5:29:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Yh8u0eF19AkKSSsuJBCfGLHKI1Vuz1eWX:Yh8uF/JXuPPns4WX

Entry address:
0x5F54

Entry point:
55, 8B, EC, 81, EC, D8, 00, 00, 00, B8, 42, 00, 00, 00, 89, 45, D0, 53, 8B, 5D, D0, 89, 5D, D0, 56, 89, 45, D0, 57, BA, D6, 97, 00, 00, 23, D0, 89, 55, D0, 33, C3, 89, 45, AC, 68, 68, 00, 41, 00, FF, 15, 20, A1, 40, 00, 0B, D8, 8B, 35, 38, 00, 41, 00, 83, FB, 46, 75, 0D, 03, DB, 83, FB, 68, 74, 06, 83, CB, 42, 89, 5D, AC, 89, 75, AC, 89, 45, 94, 89, 45, AC, 8D, 7D, D8, 57, FF, 15, F4, A0, 40, 00, 8B, 5D, AC, 83, EB, 76, 83, FB, 20, 74, 40, 8B, C6, 83, E8, EE, 89, 7D, D0, 83, FB, A7, 74, 33, 81, FB, 19, DD...
 
[+]

Entropy:
6.4751

Developed / compiled with:
Microsoft Visual C++

Code size:
33 KB (33,792 bytes)

Remove updateflashplayer_0a120c28.exe - Powered by Reason Core Security