veywcoa.exe

Emnsiem Corporatu

The executable veywcoa.exe, “Emnsiem Visatl Studie 2020” has been detected as malware by 17 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Emnsiem Corporatu

Description:
Emnsiem Visatl Studie 2020

Version:
11.31.2119.57992

MD5:
030bba9e9da6ef02fd2e6dd64164309f

SHA-1:
fcd4b0cde7c12b73c3a22ba7161a45867f980d34

SHA-256:
977cb1dd16129584a12aa884b70849e917ca859752773d9584fc91c781ecc0c7

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
4/19/2024 6:28:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.521681
6205011

Avira AntiVirus
TR/Crypt.ZPACK.Gen
7.11.196.234

avast!
Win32:Dropper-gen [Drp]
141214-1

AVG
Win32/Cryptor
2014.0.4189

Bitdefender
Gen:Variant.Kazy.521681
1.0.20.1770

Emsisoft Anti-Malware
Gen:Variant.Kazy.521681
8.14.12.20.12

ESET NOD32
Win32/Kryptik.CTMU trojan
7.0.302.0

Fortinet FortiGate
W32/Kryptik.CSQU!tr
12/20/2014

F-Secure
Gen:Variant.Kazy.521681
11.2014-20-12_7

G Data
Gen:Variant.Kazy.521681
14.12.24

Kaspersky
Trojan-Spy.Win32.Zbot
15.0.0.543

Malwarebytes
Trojan.Zemot
v2014.12.20.12

McAfee
Trojan.MysticCompressor!030BBA9E9DA6
16.8.708.2

MicroWorld eScan
Gen:Variant.Kazy.521681
15.0.0.1062

Norman
Gen:Variant.Kazy.521681
04.12.2014 14:30:06

Panda Antivirus
Trj/Genetic.gen
14.12.20.12

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.23

File size:
496.6 KB (508,486 bytes)

Product version:
11.31.2119.57992

Original file name:
baess.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\yqevnyeh\veywcoa.exe

File PE Metadata
Compilation timestamp:
3/24/2012 8:06:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:TLc/KNGOzG3Kfo++9Q08/yz2NyJ/2dBig32soRwpoMqUiSndx4:pt7j0tH52OktE84Sndx4

Entry address:
0x5350

Entry point:
55, 8B, EC, 81, EC, EC, 00, 00, 00, B9, 5A, A7, 00, 00, 89, 8D, 60, FF, FF, FF, 53, 8B, 85, 60, FF, FF, FF, 03, C0, 89, 85, 60, FF, FF, FF, 56, 81, F1, 00, 08, 82, CA, 8B, 85, 60, FF, FF, FF, 3B, C1, 75, 13, 33, C1, BA, DE, 00, 00, 00, 89, 85, 60, FF, FF, FF, 89, 95, 60, FF, FF, FF, 57, 03, CA, 8B, 35, 8C, F0, 40, 00, 89, B5, 60, FF, FF, FF, 83, F8, 2C, 74, 3F, 03, CA, BA, 96, 00, 00, 00, 89, 95, 60, FF, FF, FF, 89, 85, 60, FF, FF, FF, 89, B5, 60, FF, FF, FF, 89, B5, 60, FF, FF, FF, 83, F8, 9C, 75, 1B, 83...
 
[+]

Entropy:
6.5304

Developed / compiled with:
Microsoft Visual C++

Code size:
33 KB (33,792 bytes)

Scheduled Task
Task name:
Security Center Update - 3937319718

Trigger:
Daily (Runs daily at 3:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove veywcoa.exe - Powered by Reason Core Security