xoogy.exe

Maskaseft Visual Studio 2010

Maskaseft Corporation

The executable xoogy.exe, “Maskaseft Visual Studie 2010” has been detected as malware by 37 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Maskaseft Corporation

Product:
Maskaseft® Visual Studio® 2010

Description:
Maskaseft Visual Studie 2010

Version:
1.9.43074.5121 built by: SP1Rel

MD5:
b2322670ab93a4aa4d8f42ef52d87958

SHA-1:
ec98db04648f1f4412e7679f350f2297cb06d4a0

SHA-256:
ab06d1704a35e36686d904a737c906841c25b49ea11a494279f5c37df35e5f62

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
4/20/2024 1:02:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Bot.78115
878

Agnitum Outpost
TrojanSpy.Zbot
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2014.08.01

Avira AntiVirus
TR/Crypt.XPACK.Gen7
7.11.164.214

avast!
Win32:Dropper-gen [Drp]
2014.9-140729

AVG
SHeur4
2015.0.3398

Baidu Antivirus
Trojan.Win32.Kryptik
4.0.3.14911

Bitdefender
Backdoor.Bot.78115
1.0.20.1265

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
TrojWare.Win32.Kryptik.CHPD
19302

Dr.Web
Trojan.KillProc.32251
9.0.1.0254

Emsisoft Anti-Malware
Backdoor.Bot.78115
8.14.09.10.12

ESET NOD32
Win32/Kryptik.CHTD (variant)
8.10185

Fortinet FortiGate
W32/Zbot.CHTD!tr
9/10/2014

F-Secure
Backdoor.Bot.78115
11.2014-10-09_4

G Data
Backdoor.Bot.78115
14.9.24

IKARUS anti.virus
Trojan.Win32.Spy
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.182.12911

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3486

Malwarebytes
Spyware.Zbot.MSXGen
v2014.07.29.06

McAfee
PWSZbot-FABW!634675768221
5600.7012

Microsoft Security Essentials
PWS:Win32/Zbot.gen!AP
1.10802

MicroWorld eScan
Backdoor.Bot.78115
15.0.0.759

NANO AntiVirus
Trojan.Win32.Zbot.ddbrxh
0.28.2.61148

nProtect
Backdoor.Bot.78115
14.07.31.01

Panda Antivirus
Trj/Genetic.gen
14.09.10.12

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.11.0

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14727

Sophos
Mal/FakeAV-IS
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-FalComp
10369

Total Defense
Win32/Zbot.GSeUOLC
37.0.11140

Trend Micro House Call
TSPY_ZBOT.SMLAK
7.2.254

Trend Micro
TSPY_ZBOT.SMLAK
10.465.11

Vba32 AntiVirus
TrojanSpy.Zbot
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
31796

Zillya! Antivirus
Trojan.Zbot.Win32.162775
2.0.0.1900

File size:
296.7 KB (303,803 bytes)

Product version:
1.9.43074.5121

Copyright:
© Maskaseft Corporation. All rights reserved.

Original file name:
devonv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\yfamday\xoogy.exe

File PE Metadata
Compilation timestamp:
7/6/2010 9:45:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:0f7SENuYbvwvkaO2lopv7MMwavZSfOsk8cl+DYgu:0fWM9bikoMv7MMwPc8cgu

Entry address:
0xC988

Entry point:
55, 8B, EC, 81, EC, 0C, 01, 00, 00, BA, 37, 00, 00, 00, 81, C2, 00, 91, 02, 00, 89, 95, 08, FF, FF, FF, 53, 89, 95, 08, FF, FF, FF, 56, 03, D2, EB, 19, B9, 69, 00, 00, 00, 81, E9, 00, 18, 74, 20, 52, 68, 00, 15, 4A, 78, E8, 8A, 1F, 00, 00, 83, C4, 08, 57, 83, F8, 96, 74, 0F, 68, 00, C5, 58, 14, 6A, 7C, E8, AB, 17, 00, 00, 83, C4, 08, 50, E8, BB, 18, 00, 00, 83, C4, 04, 8D, 7D, D0, 57, FF, 15, 08, 49, 42, 00, 8B, BD, 08, FF, FF, FF, 83, F7, A9, 89, 85, 08, FF, FF, FF, 68, 00, 5D, 4B, C0, E8, 46, 1F, 00, 00...
 
[+]

Entropy:
7.8414

Developed / compiled with:
Microsoft Visual C++

Code size:
138 KB (141,312 bytes)

Scheduled Task
Task name:
Security Center Update - 631480141

Trigger:
Daily (Runs daily at 6:00 PM)

Description:
Keeps your Security Center software up to date. If this task is disabled or stopped, your Security Center software will not be kept up to date, meanin


Remove xoogy.exe - Powered by Reason Core Security