puppy_kitten_house_pet_images_001.jpg.exe

The application puppy_kitten_house_pet_images_001.jpg.exe has been detected as a potentially unwanted program by 34 anti-malware scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from www.jakeshotel.com.
MD5:
505d79d6fe74f5bdc59b73ef9164e12c

SHA-1:
65e5d865c2595724cb00ac2e71ad9f26b166c186

SHA-256:
bbad15676ef02b9b7e429e57de1f9d16e5a7a30d1a696ebffbbf090d4135a748

Scanner detections:
34 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:57:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.382344
878

Agnitum Outpost
Backdoor.Napolar
7.1.1

AhnLab V3 Security
Trojan/Win32.Ransomlock
2014.09.09

Avira AntiVirus
TR/Crypt.ZPACK.81272
7.11.171.102

avast!
Win32:Agent-ATTB [Trj]
2014.9-140909

AVG
Lebros
2015.0.3356

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.1499

Bitdefender
Gen:Variant.Kazy.382344
1.0.20.1260

Bkav FE
W32.CreautLTS.Trojan
1.3.0.4959

Comodo Security
TrojWare.Win32.Injector.BEJX
19465

Dr.Web
Trojan.PWS.Stealer.12938
9.0.1.0252

Emsisoft Anti-Malware
Gen:Variant.Kazy.382344
8.14.09.09.10

ESET NOD32
Win32/Injector.BEJX (variant)
8.10388

Fortinet FortiGate
W32/Napolar.AAY!tr.bdr
9/9/2014

F-Secure
Gen:Variant.Kazy.382344
11.2014-09-09_3

G Data
Gen:Variant.Kazy.382344
14.9.24

IKARUS anti.virus
Trojan.Lebros
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13305

Kaspersky
Backdoor.Win32.Napolar
14.0.0.3275

Malwarebytes
Spyware.Zbot.ED
v2014.09.09.10

McAfee
RDN/Generic BackDoor!yj
5600.7012

Microsoft Security Essentials
Trojan:Win32/Napolar.A
1.10904

MicroWorld eScan
Gen:Variant.Kazy.382344
15.0.0.756

NANO AntiVirus
Trojan.Win32.Inject.cywopb
0.28.2.61942

Norman
Troj_Generic.TYXKH
11.20140909

Panda Antivirus
Trj/Genetic.gen
14.09.09.10

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
Backdoor.Napolar.r5
9.14.14.00

Sophos
Mal/Zbot-QU
4.98

Trend Micro House Call
TROJ_SPNR.09F514
7.2.252

Trend Micro
TROJ_SPNR.09F514
10.465.09

Vba32 AntiVirus
Backdoor.Napolar
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
32950

Zillya! Antivirus
Trojan.Zbot.Win32.163458
2.0.0.1915

File size:
192 KB (196,608 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\puppy_kitten_house_pet_images_001.jpg.exe

File PE Metadata
Compilation timestamp:
5/1/2014 2:24:35 PM

OS version:
4.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
16.0

CTPH (ssdeep):
3072:5raNatnulhap/njThx0fxczE9vNs7/ebU1VnyeVaujdPy1lB5:6NhmjThwczovNs7WSVnFXjy7

Entry address:
0x274F

Entry point:
55, 8B, EC, 83, EC, 0C, 33, C9, B9, 01, 00, 00, 00, EB, 02, 56, 57, 8B, F9, 81, EF, 00, 00, 3A, 00, EB, 00, 51, 58, 58, 58, E8, 28, F0, FF, FF, 8B, F0, 85, F6, 59, 74, 60, 83, 65, FC, 00, 85, FF, 8D, 04, 9E, 89, 46, 0C, 8B, 45, F8, 89, 7E, 08, 8B, 40, 08, 8B, 40, 14, 8A, 40, 59, 88, 46, 04, 8B, 45, 0C, 8B, 58, 0C, 7E, 3A, 8D, 46, 10, 89, 45, 0C, 8B, 03, 8B, 4D, 08, E8, AD, 6A, FF, FF, 85, C0, 75, 06, 8B, 45, F8, 8B, 40, 2C, 8B, 4D, 0C, 8B, 55, FC, FF, 45, FC, 83, 45, 0C, 04, 89, 01, 8A, 4B, 08, 8B, 46, 0C...
 
[+]

Entropy:
7.3139

Developed / compiled with:
Microsoft Visual C++

Code size:
11.8 KB (12,032 bytes)

The file puppy_kitten_house_pet_images_001.jpg.exe has been seen being distributed by the following URL.

Remove puppy_kitten_house_pet_images_001.jpg.exe - Powered by Reason Core Security