mm-zayedmbz.exe

The executable mm-zayedmbz.exe has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address server-54-192-25-254.mxp4.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
b569e3a69e43b0e82cf304305fcddc6b

SHA-1:
8a29049ee2a102b851f0065af5e30237b9b34387

SHA-256:
c3dc8b920789793cc51f1617e1a373fbe6319460d04e763f327babae7e4725de

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/24/2024 6:41:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
17.2.13.6

File size:
916.6 KB (938,557 bytes)

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
10/26/2015 3:50:46 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
2.50

Entry address:
0x1000

Entry point:
48, 83, EC, 28, 49, C7, C0, 28, 0E, 00, 00, 48, 31, D2, 48, B9, 80, 50, 0D, 40, 01, 00, 00, 00, E8, 19, D7, 01, 00, 48, 31, C9, E8, 1D, D7, 01, 00, 48, 89, 05, 5C, 40, 0D, 00, 4D, 31, C0, 48, C7, C2, 00, 10, 00, 00, 48, 31, C9, E8, 0A, D7, 01, 00, 48, 89, 05, 3B, 40, 0D, 00, 48, B8, B0, B2, 08, 40, 01, 00, 00, 00, 48, 89, 05, E2, 41, 0D, 00, E8, 75, 2F, 03, 00, E8, 40, 22, 03, 00, E8, 4B, 20, 03, 00, E8, 2E, 0A, 03, 00, E8, 8D, F8, 02, 00, E8, 14, DA, 02, 00, E8, 3F, D7, 02, 00, E8, C6, CC, 02, 00, E8, B1...
 
[+]

Entropy:
7.1729

Code size:
475 KB (486,400 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server-54-192-55-201.jfk6.r.cloudfront.net  (54.192.55.201:443)

TCP (HTTP SSL):
Connects to server-54-192-55-120.jfk6.r.cloudfront.net  (54.192.55.120:443)

TCP (HTTP):
Connects to server-54-192-25-254.mxp4.r.cloudfront.net  (54.192.25.254:80)

TCP (HTTP):
Connects to 94.31.29.54.IPYX-077437-ZYO.above.net  (94.31.29.54:80)

Remove mm-zayedmbz.exe - Powered by Reason Core Security