Sample: 9b79e6d3151f4f8305e38949a6186912

Note: if you are new to ThreatMiner, check out the how-to page to find out how you can get the most out of this portal.

Metadata
File name:N/A
File type:PE32 executable (GUI) Intel 80386, for MS Windows
File size:3117016
Analysis date:N/A
MD5:9b79e6d3151f4f8305e38949a6186912
SHA1:6d2a0503e8aa73cd3d1ad0957f1ff74d27bf9231
SHA256:26ebf4dcb8273e8e2ff9fbdc360ad254c18df7c2d3292c6652f3c675be8f7897
SHA512:N/A
SSDEEP:N/A
IMPHASH:N/A
Authentihash:N/A
Related resources
PE TypePE32
Internal NameINCUBUS
CommentsWindows Update Manager for NT
File Size3.0 MB
Machine TypeIntel 386 or later, and compatibles
File OSWin32
Code Size147456
OS Version4.0
Entry Point0x2bd4
File Flags Mask0x0000
Linker Version6.0
File SubtypeN/A
Uninitialized Data SizeN/A
File Version6.01
Initialized Data Size69632
File DescriptionG.3
Product Version Number6.1.0.0
Product NameMicrosoft(R) Windows (R) 2000 Operating System
Company NameUMBERLLA
MIME Typeapplication/octet-stream
Character SetUnicode
Language CodeChinese (Simplified)
File Version Number6.1.0.0
File TypeWin32 EXE
Original FilenameINCUBUS.exe
Legal CopyrightCopyright (C) Microsoft Corp. 1981-1999
SubsystemWindows GUI
Object File TypeExecutable application
Image Version6.1
File Flags(none)
Subsystem Version4.0
Product Version6.01
Source:
APTNotes
Cyber threat intelligence reports associated with 9b79e6d3151f4f8305e38949a6186912.
Loading...
Domains
Domains the malware sample communicates with.
Hosts
Hosts the malware sample communicates with.
HTTP Requests
HTTP requests the malware sample makes.
AV Detections
AV detection names associated with the malware sample.
ALYacWin32.Worm.VB.NZQ
AVGGeneric10.TNK
AVwareTrojan-Downloader.Win32.VB.eex (v)
Ad-AwareWin32.Worm.VB.NZQ
AegisLabTroj.Downloader.W32.VB.l4ji
AhnLab-V3Dropper/Win32.Cosmu
Antiy-AVLTrojan/Generic.ASVCS3S.171
ArcabitWin32.Worm.VB.NZQ
AvastWin32:AutoRun-BOW [Wrm]
AviraTR/Gendal.6623041.2
BaiduWin32.Virus.VBbind.a
BitDefenderWin32.Worm.VB.NZQ
BkavW32.FamVT.Cosmu.PE
CAT-QuickHealWorm.VB.AT3
CMCTrojan.Win32.Cosmu!O
ClamAVWin.Trojan.Cosmu-4
ComodoTrojWare.Win32.TrojanDropper.Agent.~VBV
CyrenW32/Trojan-Gypikon-based.DM2!Ma
DrWebWin32.HLLW.Autoruner.6014
ESET-NOD32Win32/VB.NUP
EmsisoftWin32.Worm.VB.NZQ (B)
F-ProtW32/Trojan-Gypikon-based.DM2!Ma
F-SecureWin32.Worm.VB.NZQ
FortinetW32/AutoRun.RPV!worm
GDataWin32.Worm.VB.NZQ
IkarusTrojan-Downloader.Win32.VB
JiangminTrojan/Cosmu.lan
K7AntiVirusP2PWorm ( 0025f28c1 )
K7GWP2PWorm ( 0025f28c1 )
KasperskyVirus.Win32.Lamer.el
MalwarebytesTrojan.Downloader
McAfeeW32/Autorun.worm.i.gen
McAfee-GW-EditionBehavesLike.Win32.Autorun.vh
MicroWorld-eScanWin32.Worm.VB.NZQ
MicrosoftWorm:Win32/VB.AT
NANO-AntivirusTrojan.Win32.VB.ltch
PandaW32/OverDoom.A
Qihoo-360Virus.Win32.Lamer.B
RisingWorm.Win32.AvKiller.dr
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
SophosTroj/DwnLdr-HQY
SymantecW32.Besverit
TencentWorm.Win32.VB.kp
TheHackerTrojan/Downloader.VB.eex
TotalDefenseWin32/VB.JU
TrendMicroTROJ_DLOADR.SMM
TrendMicro-HouseCallTROJ_DLOADR.SMM
VBA32SIM.Trojan.VBO.0859
VIPRETrojan-Downloader.Win32.VB.eex (v)
ViRobotTrojan.Win32.Cosmu.887991[h]
YandexTrojan.Cosmu!swO4sNlTBQg
ZillyaDownloader.VB.Win32.95
nProtectWin32.Worm.VB.NZQ
Mutants
Mutants created by the malware sample.
Registry keys
Registry keys created by the malware sample.
Comments
User comments about 9b79e6d3151f4f8305e38949a6186912.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.