updateflashplayer_8570bc5f.exe

Maskiseft Visual Studio 2010

Maskiseft Corporation

The executable updateflashplayer_8570bc5f.exe, “Maskiseft Visual Studie 2010” has been detected as malware by 36 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Maskiseft Corporation

Product:
Maskiseft® Visual Studio® 2010

Description:
Maskiseft Visual Studie 2010

Version:
1.9.43074.5121 built by: SP1Rel

MD5:
8872b2ae83f7cd6322948a95d6ed6d06

SHA-1:
692226bd6496072677a14f13fef81d61fa594f53

SHA-256:
ef9e0cd169b26f9eff7ca5604c21794b2a56d658e3040e300909da2376c3cdee

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/26/2024 12:17:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.428451
865

Agnitum Outpost
Trojan.Injector
7.1.1

AhnLab V3 Security
Trojan/Win32.ZBot
2014.09.09

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.171.78

avast!
Win32:Dropper-gen [Drp]
2014.9-140922

AVG
Trojan horse Inject2
2015.0.3343

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.1489

Bitdefender
Gen:Variant.Kazy.428451
1.0.20.1105

Bkav FE
W32.SusterlyLTAI.Trojan
1.3.0.4959

Comodo Security
TrojWare.Win32.Injector.BJMY
19459

Dr.Web
Trojan.Siggen6.22973
9.0.1.0265

Emsisoft Anti-Malware
Gen:Variant.Kazy.428451
8.14.08.09.01

ESET NOD32
Win32/Kryptik.CIOG trojan
8.7.0.302.0

Fortinet FortiGate
W32/Kryptik.CIOG!tr
9/22/2014

F-Prot
W32/A-956a2ce4
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.428451
11.2014-22-09_2

G Data
Gen:Variant.Kazy.428451
14.9.24

IKARUS anti.virus
Trojan.Win32.Yakes
t3scan.1.7.5.0

K7 AntiVirus
Riskware
13.183.13305

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3435

Malwarebytes
Trojan.Zbot.gen
v2014.08.09.01

McAfee
PWSZbot-FABW!A28701FE06EB
5600.6999

Microsoft Security Essentials
Threat.Undefined
1.183.1966.0

MicroWorld eScan
Gen:Variant.Kazy.428451
15.0.0.795

NANO AntiVirus
Trojan.Win32.XPACK.ddsory
0.28.2.61942

Norman
Kryptik.CEFT
11.20140922

Panda Antivirus
Trj/Genetic.gen
14.09.22.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.13

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14807

Sophos
Troj/Agent-AIIM
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-FalComp
10433

Total Defense
Win32/Zbot.PSRWIQB
37.0.11170

Trend Micro House Call
TSPY_ZBOT.SMLAK
7.2.265

Trend Micro
TSPY_ZBOT.SMLAK
10.465.22

VIPRE Antivirus
Threat.4725263
32210

File size:
296 KB (303,122 bytes)

Product version:
1.9.43074.5121

Copyright:
© Maskiseft Corporation. All rights reserved.

Original file name:
divonv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_8570bc5f.exe

File PE Metadata
Compilation timestamp:
6/6/2012 6:27:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:GT6XOVCnVl24ftQEyWz1gc+j/KOxM+ttH8BlNTI:OFMyrKmgBlNE

Entry address:
0xC984

Entry point:
55, 8B, EC, 81, EC, 04, 01, 00, 00, 6A, B1, 6A, 1B, 6A, 33, E8, 7B, 1B, 00, 00, 83, C4, 0C, 53, 83, C0, 89, A9, 1B, 00, 00, 00, 75, 13, 83, F8, FB, 74, 0E, BB, 42, 7A, 00, 00, 53, E8, E3, 18, 00, 00, 83, C4, 04, 56, 3B, 45, 80, 75, 0F, 8B, 1D, 34, CA, 42, 00, 81, C3, 00, 01, 12, 71, 89, 5D, CC, 57, 03, DB, 89, 5D, 9C, 83, EB, 92, 8B, 55, 9C, 3B, 55, 88, 74, 09, 83, F3, DC, 89, 5D, 9C, 89, 55, 9C, 6A, 00, 6A, 00, 68, E5, 00, 00, 00, 68, 00, CA, 42, 00, FF, 15, EC, 4D, 42, 00, 83, F0, 0C, BB, 6E, 00, 00, 00...
 
[+]

Entropy:
7.8540

Developed / compiled with:
Microsoft Visual C++

Code size:
137.5 KB (140,800 bytes)

Remove updateflashplayer_8570bc5f.exe - Powered by Reason Core Security