amazing_food_photos_img_001.jpg.exe

MyPen

The executable amazing_food_photos_img_001.jpg.exe has been detected as malware by 40 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from www.jakeshotel.com.
Product:
MyPen

Description:
MyPen

Version:
1, 0, 0, 1

MD5:
f9d1da7c07d63f1e996310eb3afe9776

SHA-1:
9dffcfd32229929a4627fccd25580599549871fa

SHA-256:
0bd03449da6fcac37f1cb94a05fe1a081d2b503a8fc722b02be9cd6730217f11

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
2/25/2025 7:22:29 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1673927
276

AegisLab AV Signature
Troj.W32.Sharik!c
2.1.4+

Agnitum Outpost
Trojan.Sharik
7.1.1

AhnLab V3 Security
Trojan/Win32.Ransomlock
2016.03.10

Avira AntiVirus
TR/Kryptik.gta.171
8.3.3.2

Arcabit
Trojan.Generic.D198AC7
1.0.0.657

avast!
Win32:Dropper-gen [Drp]
2014.9-160504

AVG
SHeur4
2017.0.2754

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.1654

Bitdefender
Trojan.GenericKD.1673927
1.0.20.625

Bkav FE
W32.DropperAmuquizQ.Trojan
1.3.0.7744

Comodo Security
UnclassifiedMalware
24486

Dr.Web
Trojan.Hottrend
9.0.1.0125

Emsisoft Anti-Malware
Trojan.GenericKD.1673927
8.16.05.04.07

ESET NOD32
Win32/TrojanDownloader.Zurgop.BK
10.13152

Fortinet FortiGate
W32/Sharik.SMT!tr
5/4/2016

F-Prot
W32/Trojan2.ODZY
v6.4.7.1.166

F-Secure
Trojan.GenericKD.1673927
11.2016-04-05_4

G Data
Trojan.GenericKD.1673927
16.5.25

IKARUS anti.virus
Trojan-Downloader.Win32.Dofoil
t3scan.2.0.9.0

K7 AntiVirus
Trojan-Downloader
13.214.18958

Kaspersky
Trojan.Win32.Sharik
14.0.0.263

Malwarebytes
Spyware.Zbot.ED
v2016.05.04.07

McAfee
Generic.dx!F9D1DA7C07D6
5600.6410

Microsoft Security Essentials
VirTool:Win32/Injector.IA
1.1.12505.0

MicroWorld eScan
Trojan.GenericKD.1673927
17.0.0.375

NANO AntiVirus
Trojan.Win32.Inject.cxqzlc
1.0.18.6677

nProtect
Trojan.GenericKD.1673927
16.03.09.01

Panda Antivirus
Trj/WLT.A
16.05.04.07

Qihoo 360 Security
Win32/Trojan.b66
1.0.0.1120

Quick Heal
TrojanDownloader.Upatre.A4
5.16.14.00

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16502

Sophos
Mal/Zbot-QU
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Sharik
9164

Total Defense
Win32/Dofoil.NO
37.1.62.1

Trend Micro House Call
TROJ_MALKRYP.SM1
7.2.125

Trend Micro
TROJ_MALKRYP.SM1
10.465.04

Vba32 AntiVirus
Trojan.Badur
3.12.26.4

VIPRE Antivirus
Trojan-Downloader.Win32.Dofoil
47754

Zillya! Antivirus
Trojan.Sharik.Win32.1349
2.0.0.2713

File size:
76 KB (77,824 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright ? 2014

Original file name:
MyPen.exe

File type:
Executable application (Win32 EXE)

Language:
Wegierski (Wegry)

Common path:
C:\users\{user}\downloads\amazing_food_photos_img_001.jpg.exe

File PE Metadata
Compilation timestamp:
4/30/2014 5:32:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:uRNlctELCT21Wf8hI320kELX3dcNqDZsax/VbO9BbO6xDISpW:u3lUvxXTDiUVsBbdTW

Entry address:
0x1524

Entry point:
55, 8B, EC, 51, 51, 03, C0, 89, 45, FC, 8D, 45, FC, 50, 56, 8D, 45, F8, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, E8, 47, FD, FF, FF, 90, 85, C0, 75, 14, 8B, 4D, FC, 83, F9, 02, 72, 08, D1, E9, 66, 21, 04, 4E, C9, C3, 66, 83, 26, 00, C9, C3, 55, 8B, EC, 51, 57, 8D, 45, FC, 50, FF, 75, 0C, 33, FF, FF, 75, 08, E8, 76, 08, 00, 00, 83, C4, 0C, 85, C0, 75, 1E, FF, 75, 10, 8B, 45, 14, FF, 75, FC, E8, C5, FA, FF, FF, 85, C0, 59, 59, 75, 01, 47, FF, 75, FC, FF, D2, 90, 90, 90, 90, 8B, C7, 5F, C9, C3, FF, 74, 24, 0C, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

The file amazing_food_photos_img_001.jpg.exe has been seen being distributed by the following URL.

Remove amazing_food_photos_img_001.jpg.exe - Powered by Reason Core Security