setup.exe

7-Zip

Igor Pavlov

The executable setup.exe has been detected as malware by 39 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server. The file has been seen being downloaded from www.youtube.com and multiple other hosts.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7-Zip GUI

Version:
9.20

MD5:
f68c036462368d6d5dd45aa8353d569d

SHA-1:
880a473dde56e75b00e73ce5bda8adcc3387150a

SHA-256:
e7026763593f91119de0fe551108528395fd83be6e99293a0cf179cfbcb834b9

Scanner detections:
39 / 68

Status:
Malware

Analysis date:
11/15/2024 5:53:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1693385
353

Agnitum Outpost
Trojan.PWS.Fareit
7.1.1

AhnLab V3 Security
Trojan/Win32.Zbot
2015.08.17

Avira AntiVirus
TR/PSW.Fareit.2579
8.3.1.6

Arcabit
Trojan.Generic.D19D6C9
1.0.0.425

avast!
Win32:Malware-gen
2014.9-160217

AVG
Zbot
2017.0.2831

Baidu Antivirus
Trojan.Win32.InfoStealer
4.0.3.16217

Bitdefender
Trojan.GenericKD.1693385
1.0.20.240

Clam AntiVirus
Win.Trojan.Fareit-326
0.98/21511

Comodo Security
UnclassifiedMalware
23020

Dr.Web
Trojan.PWS.Stealer.1932
9.0.1.048

Emsisoft Anti-Malware
Trojan.GenericKD.1693385
8.16.02.17.11

ESET NOD32
Win32/PSW.Fareit
10.12103

Fortinet FortiGate
W32/Fareit.A!tr.pws
2/17/2016

F-Prot
W32/Trojan2.OEQE
v6.4.7.1.166

F-Secure
Trojan.GenericKD.1693385
11.2016-17-02_4

G Data
Trojan.GenericKD.1693385
16.2.25

IKARUS anti.virus
Trojan-PWS.Win32.Fareit
t3scan.1.9.5.0

K7 AntiVirus
Password-Stealer
13.2016902

Kaspersky
Trojan-PSW.Win32.Fareit
14.0.0.648

Malwarebytes
Spyware.Zbot.ED
v2016.02.17.11

McAfee
RDN/Generic PWS.y!zs
5600.6487

Microsoft Security Essentials
PWS:Win32/Fareit
1.1.11903.0

MicroWorld eScan
Trojan.GenericKD.1693385
17.0.0.144

NANO AntiVirus
Trojan.Win32.Stealer.czwera
0.30.24.3079

nProtect
Trojan.GenericKD.1693385
15.08.13.01

Panda Antivirus
Trj/WLT.A
16.02.17.11

Qihoo 360 Security
Win32/Trojan.PSW.368
1.0.0.1015

Quick Heal
Trojan.fareit.rw5
2.16.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.16CED95A!382654810
23.00.65.16215

Sophos
Mal/Generic-L
4.98

Total Defense
Win32/Fareit.ZI
37.1.62.1

Trend Micro House Call
TROJ_SPNR.15FI14
7.2.48

Trend Micro
TROJ_SPNR.15FI14
10.465.17

Vba32 AntiVirus
TrojanPSW.Fareit
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42940

ViRobot
Trojan.Win32.S.Agent.129536.AT[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Kryptik.Win32.623760
2.0.0.2353

File size:
126.5 KB (129,536 bytes)

Product version:
9.20

Copyright:
Copyright (c) 1999-2010 Igor Pavlov

Original file name:
7zg.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
7/17/1997 1:03:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:TBzkK6CtM/rjaqOWl4vXjaTEwYYLYSW+3fvIypMcYFsoazb:9glCtAeWAuTN5pPRj

Entry address:
0x1620

Entry point:
6A, 12, 68, 2E, 18, 40, 00, E8, 05, 00, 00, 00, 90, 90, 90, 90, 90, 89, 05, 1C, E0, 40, 00, 8B, 35, B4, E0, 40, 00, E8, 2B, 0E, 00, 00, 33, F0, E8, 81, 0D, 00, 00, 33, F0, E8, F6, 08, 00, 00, 33, F0, 68, B8, E0, 40, 00, E8, 53, 07, 00, 00, 33, F0, 89, 1D, C0, E0, 40, 00, 8B, 1D, C4, E0, 40, 00, 89, DA, 2B, FA, 68, C8, E0, 40, 00, E8, FF, 10, 00, 00, A3, B8, E0, 40, 00, 89, E2, E8, FC, FE, FF, FF, 3D, 7E, 00, 00, 00, 0F, 85, 52, 00, 00, 00, 56, B8, 18, 00, 00, 00, 01, 05, D7, E0, 40, 00, 64, 8B, 00, 2B, F9...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
40.5 KB (41,472 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

http://www.youtube.com/setup.exe

Remove setup.exe - Powered by Reason Core Security