zoazu.exe

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘zoazu’.
MD5:
3a578e69bee32a0972e50c822360cf6c

SHA-1:
0d0c342280f905350389d4b4426873d59ce84b5b

SHA-256:
a665f5e91c6c0e1522caafac0aa84b0521536152d90406c70868c14f86ee8684

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/3/2024 9:55:59 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Worm/Generic_vb.ABW
2013.0.4756

Clam AntiVirus
Win.Trojan.Agent-35776
0.98/23207

File size:
68 KB (69,632 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\apparatus\zoazu.exe

File PE Metadata
Compilation timestamp:
1/1/2000 6:00:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x12134

Entry point:
E8, 04, 00, 00, 00, F6, D7, F6, D7, E9, CD, FE, FF, FF, 58, 58, 58, 35, 00, 83, EC, 14, E8, B6, BE, FF, FF, EB, 3A, 8B, 21, 6E, 0F, B6, 07, 47, 86, D9, 86, D9, F9, 83, FE, 4C, 29, 04, 24, FC, 9B, F7, D7, F7, D7, 80, 3F, 00, 58, E9, 92, FD, FF, FF, 8B, 34, 87, 03, F3, 21, F9, C2, 04, 00, 8A, C8, FF, D6, EB, 2F, 02, 20, 72, 90, E9, C6, BE, FF, FF, 8D, 8D, 09, 00, 00, 00, 8B, C0, 50, 52, 6A, 0C, E9, 0A, FE, FF, FF, B1, 41, 68, 38, 9F, 29, B2, E8, 5A, FF, FF, FF, FF, D6, 85, C0, E9, 34, FC, FF, FF, 50, 42, FF...
 
[+]

Entropy:
5.5189

Code size:
40 KB (40,960 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
zoazu

Command:
C:\users\apparatus\zoazu.exe


Scan zoazu.exe - Powered by Reason Core Security