filecoach (1).exe
Classification: Malicious
filecoach (1).exe is a malicious file sample. Reported by 1 threat source, last seen 2020-03-10. Detected by 64 antivirus engines.
Detection summary
- 64 antivirus detections (19% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 8 contacted hosts
- 8 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Dropper.Dapato | Hybrid-Analysis | 2020-03-10 10:45:11 | 2020-03-10 10:45:11 |
Tags
evasiveSample information
- Filenames
- filecoach (1).exe
- File type
- PE32+ executable (GUI) x86-64, for MS Windows
- Size
- 3879112 bytes
- MD5
35a3128cdeebe8f4af05e74ef7b17bcb- SHA-1
d3102c07fe4f950c6b09f50065753f622b52d957- SHA-256
fed07785b26645cf648ee5cc702f4c70222d45c71e45332a6374db422cfdea5b- First indexed
- 2020-03-10 10:45:11
- Last updated
- 2026-09-03 00:08:44
Antivirus detections
| Engine | Detection |
|---|---|
| McAfee | Artemis!35A3128CDEEB |
| Cylance | Unsafe |
| Zillya | Dropper.Dapato.Win32.73466 |
| Sangfor | Malware |
| Alibaba | TrojanDropper:Win32/Dapato.da8169f1 |
| APEX | Malicious |
| Kaspersky | Trojan-Dropper.Win32.Dapato.qdgq |
| Rising | Dropper.Dapato!8.2A2 (CLOUD) |
| Comodo | Malware@#319dqmx7vci29 |
| McAfee-GW-Edition | Artemis!Trojan |
| AegisLab | Trojan.Win32.Dapato.b!c |
| ZoneAlarm | Trojan-Dropper.Win32.Dapato.qdgq |
| Tencent | Win32.Trojan-dropper.Dapato.Lknr |
| Qihoo-360 | Win32/Trojan.Dropper.494 |
| ALYac | Gen:Variant.Bulz.846211 |
| AVG | Win32:AdwareX-gen [Adw] |
| Alibaba | AdWare:Win32/Zoremov.5fddc295 |
| Antiy-AVL | GrayWare[AdWare]/Win32.Zoremov |
| Arcabit | Application.Agent.KCE [many] |
| Avast | Win32:AdwareX-gen [Adw] |
| Avira | ADWARE/Searcher.nmcmm |
| BitDefender | Application.Agent.KCE |
| CAT-QuickHeal | Trojan.Ghanarava.1615586759b17bcb |
| CTX | exe.adware.zoremov |
| CrowdStrike | win/grayware_confidence_100% (W) |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Adware.Searcher.3351 |
| ESET-NOD32 | Win32/Adware.Zoremov.A |
| Elastic | malicious (high confidence) |
| Emsisoft | Application.Agent.KCE (B) |
| F-Secure | Heuristic.HEUR/AGEN.1300710 |
| FireEye | Application.Agent.KCE |
| Fortinet | Riskware/Zoremov |
| GData | Trojan.GenericKD.49405216 |
| Detected | |
| Ikarus | Trojan.Spy.Stealer |
| K7AntiVirus | Adware ( 005a9dcc1 ) |
| K7GW | Adware ( 005a9dcc1 ) |
| Kaspersky | not-a-virus:HEUR:AdWare.Win32.Zoremov.gen |
| Lionic | Adware.Win32.Zoremov.2!c |
| Malwarebytes | Generic.Adware.Agent.DDS |
| MaxSecure | Trojan.Malware.122520758.susgen |
| MicroWorld-eScan | Application.Agent.KCE |
| Microsoft | Adware:Win32/Zoremov |
| Rising | Adware.Zoremov!8.11A6E (CLOUD) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious SFX |
| Sophos | Generic Reputation PUA (PUA) |
| TrendMicro | Adware.Win32.Zoremov.A |
| TrendMicro-HouseCall | Adware.Win32.Zoremov.A |
| VIPRE | Application.Agent.KCE |
| Varist | W32/ABAdware.KCRX-7749 |
| Xcitium | Malware@#319dqmx7vci29 |
| AVG | Win32:MalwareX-gen [Adw] |
| Avast | Win32:MalwareX-gen [Adw] |
| Avira | ADWARE/W32.MalwareX |
| ESET-NOD32 | Win32/RiskWare.MediaArena.F application |
| Elastic | malicious (moderate confidence) |
| F-Secure | Adware.ADWARE/W32.MalwareX |
| GData | Gen:Variant.Bulz.831646 |
| Kingsoft | Win32.Troj.Zoremov.gen |
| Paloalto | generic.ml |
| Varist | W32/ABAdware.TDQQ-7501 |
Network contacts
45.79.159.254 69.164.210.196 216.58.192.234 172.217.4.67 172.217.4.238 172.217.8.195 74.125.202.155 172.217.4.100
DNS requests
alg.zoremov.com bi.tst.zoremov.com bi.zoremov.com cache.zoremov.com mdl.zoremov.com ocsp.pki.goog service.filecoachapp.com stats.g.doubleclick.net
Process list
| Name | Command line |
|---|---|
| filecoach_1_.exe | |
| kernel.exe | |
| filecoachapp.exe | "%APPDATA%\AppDirectory\Filecoach\params.txt" |
| ie4uinit.exe | -show |
| schtasks.exe | /create /SC DAILY /TN Update_Zoremov /TR "\"%APPDATA%\AppRun\AppRun.exe\" -updatesched |