inofacweso.exe

Musrukafa Visatl Studio 2010

Musrukafa Corporatien

The executable inofacweso.exe, “Musrukafa Visatl Studie 2010” has been detected as malware by 19 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Publisher:
Musrukafa Corporatien

Product:
Musrukafa® Visatl Studio® 2010

Description:
Musrukafa Visatl Studie 2010

Version:
1.7.42074.51266 built by: SP1Rel

MD5:
aa4aca843c080a0ed8a8b8b9573b5731

SHA-1:
ff419fef16d177726dad129556c663494ad7d879

SHA-256:
6a2c77f7bfb7f99870d32fde1396fdb72289d7a2fae1b524734a4a38b6205f59

Scanner detections:
19 / 68

Status:
Malware

Analysis date:
4/26/2024 11:33:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11906322
851

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:Malware-gen
141003-0

AVG
Win32/Cryptor
2014.0.4037

Bitdefender
Trojan.Generic.11906322
1.0.20.1400

Bkav FE
HW32.Paked
1.3.0.4959

Emsisoft Anti-Malware
Trojan.Generic.11906322
8.14.10.07.11

ESET NOD32
Win32/Kryptik.CMVW (variant)
8.10524

Fortinet FortiGate
W32/Kryptik.CJJK!tr
10/7/2014

F-Secure
Trojan.Generic.11906322
11.2014-07-10_3

G Data
Trojan.Generic.11906322
14.10.24

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3138

Malwarebytes
Spyware.Zbot.MSXGen
v2014.10.07.11

Microsoft Security Essentials
Threat.Undefined
1.185.2523.0

MicroWorld eScan
Trojan.Generic.11906322
15.0.0.840

nProtect
Trojan.Generic.11906322
14.10.07.01

Panda Antivirus
Trj/Genetic.gen
14.10.07.11

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141005

File size:
271.5 KB (278,041 bytes)

Product version:
1.7.42074.51266

Copyright:
© Musrukafa Corporatien. All rights reserved.

Original file name:
dimink.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\syswow64\inofacweso.exe

File PE Metadata
Compilation timestamp:
6/28/2011 5:41:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:hunAVHh1LiWK1jduCE24PjGHc7IG7pX5wwpMn7eg3dNGOd:hjVHh1LiWU5u35PjnIUpwwi7e2XGW

Entry address:
0x6CC8

Entry point:
55, 8B, EC, 81, EC, 18, 01, 00, 00, 8B, 15, 6C, 40, 44, 00, 89, 55, E8, 53, 8B, 55, E8, EB, 0B, 83, FF, 97, 74, 06, 89, 9D, FC, FE, FF, FF, 56, EB, 0E, 2B, CB, 8B, 05, 78, 40, 44, 00, 89, 45, A4, 89, 4D, B0, 57, 33, C8, 83, F9, D5, 75, 03, 89, 4D, E8, 8B, 45, E8, 89, 45, F8, 68, 78, 40, 44, 00, FF, 15, EC, 35, 44, 00, 83, F8, 10, 74, 13, 3B, 05, 2C, 40, 44, 00, 74, 0B, 3B, 45, E8, 74, 06, 89, 85, 58, FF, FF, FF, 89, 85, 2C, FF, FF, FF, 8B, C8, 33, C8, E9, 96, 00, 00, 00, 83, FE, 46, 0F, 85, 8D, 00, 00, 00...
 
[+]

Entropy:
7.8856

Developed / compiled with:
Microsoft Visual C++

Code size:
37 KB (37,888 bytes)

Remove inofacweso.exe - Powered by Reason Core Security