MALICIOUS — 31285383519ccf172d13e18048801f2246bad353502a4a75a528c7b2612a2206
MALICIOUS — 31285383519ccf172d13e18048801f2246bad353502a4a75a528c7b2612a2206 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Zbot family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
31285383519ccf172d13e18048801f2246bad353502a4a75a528c7b2612a2206 - SHA-1:
ec96547dd2f8b2b744f7ecc4f378573124cf3759 - MD5:
9f17351f386ab03b6c82a31d2f0fdcce - imphash:
d304ef8e9e8393c0028c6e2332cf21b3 - ssdeep:
192:ukkg2yzlGuNL+flJg0mySj3TUMz0k6DAJM:ukkHfMx3TUMQklu - TLSH:
T1452C81AD42860F19C13164695936998EE15F74E23A7BB70E1F8FD12D81C00638D7C4AF - Submitted as: 31285383519ccf172d13e18048801f2246bad353502a4a75a528c7b2612a2206
- File type: pe · Size: 24948 bytes
- Verdict: malicious (86/100) · Family: Zbot
Detections (5 of 52 engines)
- ClamAV (daily): Win.Trojan.Zbot-57365
- Microsoft Defender: TrojanDownloader:Win32/Zemot.A
- Emsisoft (Emergency Kit): Trojan.Downloader.JQMF
- Trellix Stinger (McAfee): PWSZbot-FVN!9F17351F386A
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Trojan.Zbot-57365 (rule
Win.Trojan.Zbot-57365) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\george\Desktop\program.exe
- C:\75ff6729099455c4ccfaf27ee0da2d3993607f25130ebbee8eb9449c4e00f5ea
- C:\4ded2da3a508c4c063b0f2c24fc9fc6edb09f069a576e70006f2fc9b2f2c423c
- C:\2f9eb366c6e227dcbea7609deffe496ec8b124aa6416098f401e223b73861050
- C:\f8190826cdb01089cbf34c3dbdfe935bd566b71aa9949a69ade3156c231f42bf
- C:\Users\admin\Downloads\firefox_updater.exe
- C:\Users\george\Desktop\firefox_updater.exe
- C:\Users\admin\Downloads\584f522d619196cd0f9efa09cca87e908becf5559860571baf316b9fdec23f7d.exe
- C:\8cd4f353f826a0618d716b966b8dc8048d0fab181b1c6375d94584d256aa3354
- C:\67ef7a5c47e2ef98fb4db90ca6337e81a03ccd10754a027f0932403e59175d10
- C:\sample.exe
- C:\Users\admin\Downloads\file000_firefox_updater.exe
More Zbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report