updateflashplayer_b20c41c2.exe

MapMark

The executable updateflashplayer_b20c41c2.exe, “MapMark Microsoft ” has been detected as malware by 20 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Product:
MapMark

Description:
MapMark Microsoft

Version:
1, 0, 0, 1

MD5:
5e040dd4ca618cedcc9012899bd296af

SHA-1:
c51cc206558b4de0d0073bec8c9cbd514a79b8be

SHA-256:
8e2a77c7497131725129373be20bb25aa75812314c6c0cfd78d5e3ce29aacee0

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
4/27/2024 1:22:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1568116
887

AhnLab V3 Security
Spyware/Win32.Zbot
2014.02.20

avast!
Win32:Downloader-UYN [Trj]
2014.9-140901

AVG
Generic_r
2015.0.3365

Bitdefender
Trojan.GenericKD.1568116
1.0.20.1220

Dr.Web
Trojan.Winlock.8004
9.0.1.0244

Emsisoft Anti-Malware
Trojan.GenericKD.1568116
8.14.09.01.04

ESET NOD32
Win32/Injector.AXQN (variant)
8.9442

Fortinet FortiGate
W32/Zbot.HNO!tr
9/1/2014

F-Secure
Trojan.GenericKD.1568116
11.2014-01-09_2

G Data
Trojan.GenericKD.1568116
14.9.24

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3319

Malwarebytes
Trojan.Agent.ED
v2014.09.01.04

McAfee
RDN/Generic PUP.z!du
5600.7021

Microsoft Security Essentials
VirTool:Win32/CeeInject.gen!KK
1.10302

MicroWorld eScan
Trojan.GenericKD.1568116
15.0.0.732

NANO AntiVirus
Trojan.Win32.Carberp.ctkowx
0.28.0.57630

nProtect
Trojan.GenericKD.1568116
14.02.19.01

Panda Antivirus
Trj/dtcontx.K
14.09.01.04

Qihoo 360 Security
HEUR/Malware.QVM07.Gen
1.0.0.1015

File size:
222.3 KB (227,641 bytes)

Product version:
1, 0, 0, 1

Copyright:
(C) 2007

Original file name:
MapMark.EXE

File type:
Executable application (Win32 EXE)

Language:
Allemand (Autriche)

Common path:
C:\users\{user}\appdata\local\temp\updateflashplayer_b20c41c2.exe

File PE Metadata
Compilation timestamp:
2/11/2014 6:17:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:jUYjpq4MbI75+LqiPSopXKileZoCN/ZJ3I+ts2I/dopTqQSvKURyv5Ydm:jUYdbYI7ILqixUiEKi/EYvauJqFE3

Entry address:
0x10ABF

Entry point:
55, 8B, EC, 6A, FF, 68, 38, 30, 41, 00, 68, 4C, 0C, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 30, 24, 41, 00, 59, 83, 0D, 64, 59, 41, 00, FF, 83, 0D, 68, 59, 41, 00, FF, FF, 15, 2C, 24, 41, 00, 8B, 0D, 38, 59, 41, 00, 89, 08, FF, 15, 28, 24, 41, 00, 8B, 0D, 34, 59, 41, 00, 89, 08, A1, 24, 24, 41, 00, 8B, 00, A3, 60, 59, 41, 00, E8, 1D, 01, 00, 00, 39, 1D, E0, 55, 41, 00, 75, 0C, 68, 48, 0C, 41, 00, FF, 15, 20, 24...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
68 KB (69,632 bytes)

Remove updateflashplayer_b20c41c2.exe - Powered by Reason Core Security