fsbot.exe

The application fsbot.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. While running, it connects to the Internet address webcluster-ssl2.webpod5-cph3.one.com on port 80 using the HTTP protocol.
MD5:
fe63a43ca8b6c97db3d75b3510634420

SHA-1:
a056b14e3afb1ca55b5150c111d81ebe986cecd3

SHA-256:
e770c62a5b3611bbfe749cba8409a499c5ed574db06b9f2402034abf1248190e

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 7:53:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.93119
535

Avira AntiVirus
TR/Strictor.2600448
8.3.1.6

Arcabit
Trojan.Strictor.D16BBF
1.0.0.425

avast!
AutoIt:MalOb-GZ [PUP]
2014.9-150819

Bitdefender
Gen:Variant.Strictor.93119
1.0.20.1155

Clam AntiVirus
Win.Trojan.Agent-908782
0.98/21511

Emsisoft Anti-Malware
Gen:Variant.Strictor.93119
8.15.08.19.08

ESET NOD32
Win32/Packed.Autoit.H suspicious
9.12110

F-Secure
Gen:Variant.Strictor.93119
11.2015-19-08_4

G Data
Gen:Variant.Strictor.93119
15.8.25

MicroWorld eScan
Gen:Variant.Strictor.93119
16.0.0.693

Vba32 AntiVirus
AdWare.MSIL.DomaIQ
3.12.26.4

Zillya! Antivirus
Trojan.Bladabindi.Win32.43997
2.0.0.2354

File size:
2.5 MB (2,600,448 bytes)

File type:
Executable application (Win32 EXE)

Language:
Anglictina (Spojené království)

Common path:
C:\users\{user}\downloads\fsbot\fsbot\fsbot.exe

File PE Metadata
Compilation timestamp:
8/17/2015 8:34:50 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:jI0c++OCvkGsUWa8viAAWGzX7cFfdkO7HK3tPxI9Q64PKmgR+nMY:EB3vkJUnANeQFVkO7sq9Q64ymgT

Entry address:
0x27DCD

Entry point:
E8, B5, D0, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, FC, 31, 4C, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 24, E3, 4B, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, FC, 31, 4C, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8...
 
[+]

Code size:
567.5 KB (581,120 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ns197.altervista.org  (144.76.74.110:80)

TCP (HTTP):
Connects to webcluster-ssl2.webpod5-cph3.one.com  (46.30.215.63:80)

TCP (HTTP):
Connects to minhaoi.com.br  (200.223.247.114:80)

Remove fsbot.exe - Powered by Reason Core Security