bor.exe

TODO:

TODO: <Company name>

The executable bor.exe, “TODO: <File description>” has been detected as malware by 26 anti-virus scanners. This is a setup program which is used to install the application. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from idse.imss.gob.mxii.cf.
Publisher:
TODO:

Product:
TODO: <Product name>

Description:
TODO: <File description>

Version:
1.0.0.1

MD5:
c0ef4ab1bcc643006b9978c6d8f7e015

SHA-1:
3cf0e8bd5cf1c6f3e47f32c73441691fe60a6ec8

SHA-256:
3358103cab35cd759a0900d25f11cdcb4192aa0e3819f0a00b2b91306d908d97

Scanner detections:
26 / 68

Status:
Malware

Analysis date:
1/13/2025 8:36:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.775554
286

AhnLab V3 Security
Malware/Win32.Generic
2015.12.11

Avira AntiVirus
TR/Crypt.ZPACK.218522
8.3.2.4

Arcabit
Trojan.Kazy.DBD582
1.0.0.629

avast!
Win32:Malware-gen
2014.9-160424

AVG
Inject3
2017.0.2764

Baidu Antivirus
Trojan.Win32.Zbot
4.0.3.16424

Bitdefender
Gen:Variant.Kazy.775554
1.0.20.575

Dr.Web
Trojan.PWS.Panda.7934
9.0.1.0115

Emsisoft Anti-Malware
Gen:Variant.Kazy.775554
8.16.04.24.11

ESET NOD32
Win32/Spy.Zbot.YW
10.12706

Fortinet FortiGate
W32/Yakes.NOZF!tr
4/24/2016

F-Secure
Gen:Variant.Kazy.775554
11.2016-24-04_1

G Data
Gen:Variant.Kazy.775554
16.4.25

IKARUS anti.virus
Trojan-Spy.Agent
t3scan.1.9.5.0

K7 AntiVirus
Spyware
13.212.18079

Kaspersky
Trojan.Win32.Yakes
14.0.0.313

Malwarebytes
Trojan.Zbot
v2016.04.24.11

McAfee
RDN/Generic PWS.y
5600.6420

Microsoft Security Essentials
PWS:Win32/Zbot
1.1.12300.0

MicroWorld eScan
Gen:Variant.Kazy.775554
17.0.0.345

NANO AntiVirus
Trojan.Win32.Panda.dyycdc
1.0.10.5081

Panda Antivirus
Generic Suspicious
16.04.24.11

Qihoo 360 Security
HEUR/QVM20.1.Malware.Gen
1.0.0.1077

Vba32 AntiVirus
Heur.Malware-Cryptor.Filecoder
3.12.26.4

ViRobot
Trojan.Win32.A.Yakes.503296.C[h]
2014.3.20.0

File size:
491.5 KB (503,296 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2015

Original file name:
uuihzuhiaz.exe

File type:
Executable application (Win32 EXE)

Language:
French (France)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bor.exe

File PE Metadata
Compilation timestamp:
11/27/2015 1:44:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:BmNA3voK9goa+GZxbqxX+fcZdT67p4pRJtT:Bme3Ra1ZlS68t6mRJp

Entry address:
0x1400

Entry point:
55, 8B, EC, E8, 18, FD, FF, FF, 6A, 1D, E8, F1, FB, FF, FF, 83, C4, 04, E8, B9, FF, FF, FF, E8, 74, F5, 00, 00, E8, 4F, FD, FF, FF, E8, 6A, FD, FF, FF, E8, 65, FD, FF, FF, E8, 60, FD, FF, FF, 68, D0, 07, 00, 00, E8, 66, EF, 00, 00, 83, C4, 04, E8, 1E, C6, 00, 00, 33, C0, 5D, C2, 10, 00, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 28, FF, 15, 2C, 30, 41, 00, 6A, 00, FF, 15, 30, 30, 41, 00, FF, 15, 1C, 30, 41, 00, 6A, 00, FF, 15, 18, 30, 41, 00, 6A, 00, 6A, 00, FF, 15, 14, 30, 41, 00, 6A, 00, 6A, 00...
 
[+]

Entropy:
7.9134

Developed / compiled with:
Microsoft Visual C++

Code size:
68.5 KB (70,144 bytes)

The file bor.exe has been seen being distributed by the following URL.

Remove bor.exe - Powered by Reason Core Security