MSN PASSWORD CRACKER V6.5 BETA.exe

MSN PASSWORD CRACKER V6.5 BETA

The executable MSN PASSWORD CRACKER V6.5 BETA.exe has been detected as malware by 23 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from download1300.mediafire.com and multiple other hosts.
Product:
MSN PASSWORD CRACKER V6.5 BETA

Version:
1.0.0.0

MD5:
57f4bf79ee9ab156970999a53ee35069

SHA-1:
49be7c3cdd1c9a5fab147aff5f74436beba1cdcf

SHA-256:
7225a09dc2d084f9a104d67d76b9114f38a1eeb7f96c0d9cb3d52c32a3ddfcb4

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/24/2025 8:17:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.6701281
579

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
HackTool/Win32.MsnPwsHack
2015.03.05

Avira AntiVirus
TR/Agent.xct
7.11.213.138

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150705

AVG
Agent3
2016.0.3057

Bitdefender
Trojan.Generic.6701281
1.0.20.930

Clam AntiVirus
Win.Trojan.7772549-1
0.98/21511

Emsisoft Anti-Malware
Trojan.Generic.6701281
8.15.07.05.10

Fortinet FortiGate
W32/Dx.XCT!tr
7/5/2015

F-Secure
Trojan.Generic.6701281
11.2015-05-07_1

G Data
Trojan.Generic.6701281
15.7.25

IKARUS anti.virus
Trojan.Win32.Webprefix
t3scan.1.8.6.0

Malwarebytes
HackTool.PassWords
v2015.07.05.10

McAfee
Artemis!57F4BF79EE9A
5600.6713

MicroWorld eScan
Trojan.Generic.6701281
16.0.0.558

Norman
Agent.VCWL
11.20150705

nProtect
Trojan.Generic.6701281
15.03.04.01

Qihoo 360 Security
Win32/Trojan.320
1.0.0.1015

SUPERAntiSpyware
Trojan.Agent/Gen-Webprefix
9771

Trend Micro House Call
TROJ_WEBPREFIX_0000004.TOMA
7.2.186

VIPRE Antivirus
Trojan.Win32.Generic
38130

ViRobot
Trojan.Win32.A.Zbot.164864.EJ[h]
2014.3.20.0

File size:
161 KB (164,864 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2009

Original file name:
MSN PASSWORD CRACKER V6.5 BETA.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\msn password cracker v6.5 beta.exe

File PE Metadata
Compilation timestamp:
6/13/2009 11:48:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:ze8eg8IkVuCE7NVKubr0txsdoUFbtbIdmfYiDN1j+++++++++++++++++++++++T:eg8INhrqxsTbRWWlDN9++++++++++++W

Entry address:
0x6E6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0660

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
20 KB (20,480 bytes)

The file MSN PASSWORD CRACKER V6.5 BETA.exe has been seen being distributed by the following 3 URLs.

http://download1300.mediafire.com/0sds5xdfr5ig/.../MSN PASSWORD CRACKER V6.5 BETA.exe

Remove MSN PASSWORD CRACKER V6.5 BETA.exe - Powered by Reason Core Security