Zipus.exe

EUROGRAND ALLIANCE LTD

The application Zipus.exe by EUROGRAND ALLIANCE has been detected as a potentially unwanted program by 18 anti-malware scanners.
Publisher:
EUROGRAND ALLIANCE LTD  (signed and verified)

Description:
Zipus

Version:
1.1.1.21

MD5:
7d84ab17a378a73cd1c33bb1de7c2ce1

SHA-1:
6c284ffa007cf7a6e7d3a4ca7a4d4685e0763ad3

SHA-256:
727c488ccde5b1ebe71a344a31a8686c17082fe9dec839d52294cb416cc6b28b

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 10:52:02 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
VirTool.ArchSMS
7.1.1

Avira AntiVirus
KIT/ArchSMS.q
7.11.97.32

AVG
SHeur4
2017.0.2827

Bitdefender
Trojan.Generic.6780543
1.0.20.255

Dr.Web
Trojan.DownLoader5.6745
9.0.1.051

Emsisoft Anti-Malware
Trojan.Generic.6780543
8.16.02.20.01

F-Secure
Trojan.Generic.6780543
11.2016-20-02_7

G Data
Trojan.Generic.6780543
16.2.22

IKARUS anti.virus
Constructor.Win32.ArchSMS
t3scan.2.0.127

Kaspersky
Constructor.Win32.ArchSMS
14.0.0.632

McAfee
Artemis!7D84AB17A378
5600.6483

MicroWorld eScan
Trojan.Generic.6780543
17.0.0.153

NANO AntiVirus
Riskware.Win32.ArchSMS.bgysqu
0.26.0.53954

Norman
Suspicious_Gen2.RSUDF
11.20160220

Panda Antivirus
Trj/CI.A
16.02.20.01

Sophos
Generic PUA GM
4.91

Trend Micro House Call
TROJ_GEN.R15B1F1
7.2.51

VIPRE Antivirus
Trojan.Win32.Generic
20612

File size:
1.1 MB (1,122,632 bytes)

Original file name:
Zipus.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\zipus.exe

Digital Signature
Authority:
EUROGRAND ALLIANCE LTD

Valid from:
1/10/2009 3:00:00 AM

Valid to:
1/11/2030 2:59:59 AM

Subject:
E=realbarons@gmail.com, CN=Zipus, O=EUROGRAND ALLIANCE LTD, L=Mahe, C=SC

Issuer:
E=realbarons@gmail.com, CN=Zipus, O=EUROGRAND ALLIANCE LTD, L=Mahe, C=SC

Serial number:
3499E1961C224647A41A531FF35C9F40

File PE Metadata
Compilation timestamp:
9/17/2009 1:12:59 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
24576:UELo+JwPy24e0Naeju8TpaESlragl1Ow6tUB7d658Kd0TQnU7W:UwzJgyteoal8TpaEVgl1BEOd5+aW

Entry address:
0xE45610

Entry point:
60, BE, 00, 70, 13, 01, 8D, BE, 00, A0, 2C, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9235

Packer / compiler:
UPX 2.90LZMA

Code size:
1.1 MB (1,110,016 bytes)

Remove Zipus.exe - Powered by Reason Core Security