filecoach (1).exe

Classification: Malicious

filecoach (1).exe is a malicious file sample. Reported by 1 threat source, last seen 2020-03-10. Detected by 64 antivirus engines.

Detection summary

  • 64 antivirus detections (19% detection ratio)
  • 0 IDS alerts
  • 5 processes observed
  • 8 contacted hosts
  • 8 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Dropper.Dapato Hybrid-Analysis 2020-03-10 10:45:11 2020-03-10 10:45:11

Tags

evasive

Sample information

Filenames
filecoach (1).exe
File type
PE32+ executable (GUI) x86-64, for MS Windows
Size
3879112 bytes
MD5
35a3128cdeebe8f4af05e74ef7b17bcb
SHA-1
d3102c07fe4f950c6b09f50065753f622b52d957
SHA-256
fed07785b26645cf648ee5cc702f4c70222d45c71e45332a6374db422cfdea5b
First indexed
2020-03-10 10:45:11
Last updated
2026-09-03 00:08:44

Antivirus detections

EngineDetection
McAfeeArtemis!35A3128CDEEB
CylanceUnsafe
ZillyaDropper.Dapato.Win32.73466
SangforMalware
AlibabaTrojanDropper:Win32/Dapato.da8169f1
APEXMalicious
KasperskyTrojan-Dropper.Win32.Dapato.qdgq
RisingDropper.Dapato!8.2A2 (CLOUD)
ComodoMalware@#319dqmx7vci29
McAfee-GW-EditionArtemis!Trojan
AegisLabTrojan.Win32.Dapato.b!c
ZoneAlarmTrojan-Dropper.Win32.Dapato.qdgq
TencentWin32.Trojan-dropper.Dapato.Lknr
Qihoo-360Win32/Trojan.Dropper.494
ALYacGen:Variant.Bulz.846211
AVGWin32:AdwareX-gen [Adw]
AlibabaAdWare:Win32/Zoremov.5fddc295
Antiy-AVLGrayWare[AdWare]/Win32.Zoremov
ArcabitApplication.Agent.KCE [many]
AvastWin32:AdwareX-gen [Adw]
AviraADWARE/Searcher.nmcmm
BitDefenderApplication.Agent.KCE
CAT-QuickHealTrojan.Ghanarava.1615586759b17bcb
CTXexe.adware.zoremov
CrowdStrikewin/grayware_confidence_100% (W)
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebAdware.Searcher.3351
ESET-NOD32Win32/Adware.Zoremov.A
Elasticmalicious (high confidence)
EmsisoftApplication.Agent.KCE (B)
F-SecureHeuristic.HEUR/AGEN.1300710
FireEyeApplication.Agent.KCE
FortinetRiskware/Zoremov
GDataTrojan.GenericKD.49405216
GoogleDetected
IkarusTrojan.Spy.Stealer
K7AntiVirusAdware ( 005a9dcc1 )
K7GWAdware ( 005a9dcc1 )
Kasperskynot-a-virus:HEUR:AdWare.Win32.Zoremov.gen
LionicAdware.Win32.Zoremov.2!c
MalwarebytesGeneric.Adware.Agent.DDS
MaxSecureTrojan.Malware.122520758.susgen
MicroWorld-eScanApplication.Agent.KCE
MicrosoftAdware:Win32/Zoremov
RisingAdware.Zoremov!8.11A6E (CLOUD)
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious SFX
SophosGeneric Reputation PUA (PUA)
TrendMicroAdware.Win32.Zoremov.A
TrendMicro-HouseCallAdware.Win32.Zoremov.A
VIPREApplication.Agent.KCE
VaristW32/ABAdware.KCRX-7749
XcitiumMalware@#319dqmx7vci29
AVGWin32:MalwareX-gen [Adw]
AvastWin32:MalwareX-gen [Adw]
AviraADWARE/W32.MalwareX
ESET-NOD32Win32/RiskWare.MediaArena.F application
Elasticmalicious (moderate confidence)
F-SecureAdware.ADWARE/W32.MalwareX
GDataGen:Variant.Bulz.831646
KingsoftWin32.Troj.Zoremov.gen
Paloaltogeneric.ml
VaristW32/ABAdware.TDQQ-7501

Network contacts

45.79.159.254 69.164.210.196 216.58.192.234 172.217.4.67 172.217.4.238 172.217.8.195 74.125.202.155 172.217.4.100

DNS requests

alg.zoremov.com bi.tst.zoremov.com bi.zoremov.com cache.zoremov.com mdl.zoremov.com ocsp.pki.goog service.filecoachapp.com stats.g.doubleclick.net

Process list

NameCommand line
filecoach_1_.exe
kernel.exe
filecoachapp.exe"%APPDATA%\AppDirectory\Filecoach\params.txt"
ie4uinit.exe-show
schtasks.exe/create /SC DAILY /TN Update_Zoremov /TR "\"%APPDATA%\AppRun\AppRun.exe\" -updatesched