e6d8.exe

FileZilla

FileZilla Project

The executable e6d8.exe, “FileZilla FTP Client” has been detected as malware by 34 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WINSXS32’.
Publisher:
FileZilla Project

Product:
FileZilla

Description:
FileZilla FTP Client

Version:
3.5.1

MD5:
636450424226df526a3a337410fcf1af

SHA-1:
23d3739c8a5cce5ab29ae79ff8aa1606cce4c381

SHA-256:
e96c9541e263dc1645aac34a8dfb9f4c09241ce31d819df3fc1c975783eb4a64

Scanner detections:
34 / 68

Status:
Malware

Analysis date:
4/1/2025 7:57:04 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.219035
-40

Agnitum Outpost
Trojan.CoinMiner
7.1.1

AhnLab V3 Security
Dropper/Win32.Injector
2014.11.14

Avira AntiVirus
TR/Vicenor.A.141
7.11.185.104

avast!
Win32:Napolar-H [Cryp]
2014.9-170315

AVG
SHeur4
2018.0.2438

Baidu Antivirus
Trojan.Win32.CoinMiner
4.0.3.17315

Bitdefender
Gen:Variant.Kazy.219035
1.0.20.370

Bkav FE
HW32.Packed
1.3.0.4959

Comodo Security
TrojWare.Win32.Injector.AICD
20073

Dr.Web
Trojan.Siggen4.40328
9.0.1.074

Emsisoft Anti-Malware
Gen:Variant.Kazy.219035
8.17.03.15.04

ESET NOD32
Win32/CoinMiner.CT
11.10721

Fortinet FortiGate
W32/CoinMiner.CT!tr
3/15/2017

F-Secure
Gen:Variant.Kazy.219035
11.2017-15-03_4

G Data
Gen:Variant.Kazy.219035
17.3.24

IKARUS anti.virus
Backdoor.Win32.Ruskill
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.14007

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.-1313

Malwarebytes
Trojan.Agent.FUFV
v2017.03.15.04

McAfee
Trojan-FCER!636450424226
5600.6094

Microsoft Security Essentials
Trojan:Win32/Vicenor
1.11104

MicroWorld eScan
Gen:Variant.Kazy.219035
18.0.0.222

NANO AntiVirus
Trojan.Win32.Siggen4.bvgwix
0.28.6.63362

Norman
Suspicious_Gen5.AASQL
11.20170315

Panda Antivirus
Generic Malware
17.03.15.04

Qihoo 360 Security
Win32/Trojan.e6d
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.15230E91!354619025
23.00.65.17313

Sophos
Mal/Generic-S
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Skelten
8534

Trend Micro House Call
TROJ_SPNR.11FR13
7.2.74

Trend Micro
TROJ_SPNR.11FR13
10.465.15

VIPRE Antivirus
Trojan.Win32.Generic
34772

Zillya! Antivirus
Trojan.CoinMiner.Win32.541
2.0.0.1982

File size:
290.5 KB (297,472 bytes)

Product version:
3.5.1

Copyright:
FileZilla Project

Original file name:
FileZilla_3.5.1_win32-setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\e6d8.exe

File PE Metadata
OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.52

Entry address:
0x45588

Entry point:
55, 8B, EC, 53, 56, 57, BB, 00, 80, 44, 00, 66, F7, 05, 6A, 55, 44, 00, 04, 00, 75, 05, E9, 2F, 04, 00, 00, E9, 2D, 02, 00, 00, FF, 15, 98, A1, 44, 00, 83, F8, FF, F9, 74, 54, 89, 83, D0, 03, 00, 00, C7, 83, D8, 03, 00, 00, 00, 00, 00, 00, C7, 83, D4, 03, 00, 00, 00, 00, 00, 00, E8, E1, 02, 00, 00, 72, 33, 89, 83, D4, 03, 00, 00, 66, C7, 80, AC, 00, 00, 00, 08, 00, E8, 0E, 00, 00, 00, 4D, 53, 20, 53, 61, 6E, 73, 20, 53, 65, 72, 69, 66, 00, 5E, FC, B9, 0E, 00, 00, 00, 8D, 78, 6C, 33, C0, AC, 66, AB, E2, FB...
 
[+]

Entropy:
7.8990

Developed / compiled with:
Microsoft Visual C++

Code size:
280.1 KB (286,841 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WINSXS32

Command:
C:\users\{user}\appdata\roaming\e6d8.exe


Remove e6d8.exe - Powered by Reason Core Security