amazing_food_photos_img_12.jpg.exe

MyPen

The executable amazing_food_photos_img_12.jpg.exe has been detected as malware by 37 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from www.disaronno.com.
Product:
MyPen

Description:
MyPen

Version:
1, 0, 0, 1

MD5:
ce4b5867fbf6e563061090167d189e0b

SHA-1:
2c0a28835965e2fc4478f767bf5db44e6efcdfae

SHA-256:
ad2271dbf5cc522c707874e383c8f4009c41487fd3855361350dfcc1906b9c77

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
11/23/2024 7:40:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1674309
351

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Ransomlock
2015.12.15

Avira AntiVirus
TR/Agent.dleo.114
8.3.2.4

Arcabit
Trojan.Generic.D198C45
1.0.0.629

avast!
Win32:Rootkit-gen [Rtk]
2014.9-160218

AVG
SHeur4
2017.0.2829

Baidu Antivirus
Trojan.Win32.Napolar
4.0.3.16218

Bitdefender
Trojan.GenericKD.1674309
1.0.20.245

Comodo Security
UnclassifiedMalware
23765

Dr.Web
Trojan.Hottrend
9.0.1.049

Emsisoft Anti-Malware
Trojan.GenericKD.1674309
8.16.02.18.07

ESET NOD32
Win32/Napolar
10.12721

Fortinet FortiGate
W32/Krypt.DE!tr
2/18/2016

F-Prot
W32/Trojan2.OEXE
v6.4.7.1.166

F-Secure
Trojan.GenericKD.1674309
11.2016-18-02_5

G Data
Trojan.GenericKD.1674309
16.2.25

IKARUS anti.virus
Trojan.Win32.Dynamer
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.212.18103

Kaspersky
Trojan.Win32.Agent
14.0.0.641

Malwarebytes
Spyware.Zbot.ED
v2016.02.18.07

McAfee
Generic.dx!CE4B5867FBF6
5600.6485

Microsoft Security Essentials
Trojan:Win32/Bagsu!rfn
1.1.12300.0

MicroWorld eScan
Trojan.GenericKD.1674309
17.0.0.147

NANO AntiVirus
Trojan.Win32.Scarsi.czbzdh
1.0.10.5081

nProtect
Trojan.GenericKD.1674309
15.12.14.01

Panda Antivirus
Trj/WLT.A
16.02.18.07

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1077

Quick Heal
TrojanDownloader.Upatre.A4
2.16.14.00

SUPERAntiSpyware
Trojan.Agent/Gen-Upatre
9315

Total Defense
Win32/CInject.ABZ
37.1.62.1

Trend Micro House Call
TROJ_SPNR.06ES14
7.2.49

Trend Micro
TROJ_SPNR.06ES14
10.465.18

Vba32 AntiVirus
Trojan.Agent
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
45828

ViRobot
Trojan.Win32.Z.Agent.176128.A[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Agent.Win32.481708
2.0.0.2562

File size:
172 KB (176,128 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright ? 2014

Original file name:
MyPen.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\amazing_food_photos_img_12.jpg.exe

File PE Metadata
Compilation timestamp:
4/30/2014 6:32:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:CHlZv338ZyPK2h/VuJYEycNPdLN0XSkj49LSthdhH60fDPeoUPQC+RSTGOgW:CHl53sZMCJYsBuXSm4MdF60fSQSvh

Entry address:
0x1524

Entry point:
55, 8B, EC, 51, 51, 03, C0, 89, 45, FC, 8D, 45, FC, 50, 56, 8D, 45, F8, 50, 6A, 00, FF, 75, 0C, FF, 75, 08, E8, 47, FD, FF, FF, 90, 85, C0, 75, 14, 8B, 4D, FC, 83, F9, 02, 72, 08, D1, E9, 66, 21, 04, 4E, C9, C3, 66, 83, 26, 00, C9, C3, 55, 8B, EC, 51, 57, 8D, 45, FC, 50, FF, 75, 0C, 33, FF, FF, 75, 08, E8, 76, 08, 00, 00, 83, C4, 0C, 85, C0, 75, 1E, FF, 75, 10, 8B, 45, 14, FF, 75, FC, E8, C5, FA, FF, FF, 85, C0, 59, 59, 75, 01, 47, FF, 75, FC, FF, D2, 90, 90, 90, 90, 8B, C7, 5F, C9, C3, FF, 74, 24, 0C, E8...
 
[+]

Entropy:
7.5173

Developed / compiled with:
Microsoft Visual C++

Code size:
8 KB (8,192 bytes)

The file amazing_food_photos_img_12.jpg.exe has been seen being distributed by the following URL.

Remove amazing_food_photos_img_12.jpg.exe - Powered by Reason Core Security