mgassist.exe

Beijing AmazGame Age Internet Technology Co., Ltd.

The application mgassist.exe by Beijing AmazGame Age Internet Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a windows Service named “MgAssist Service”.
Publisher:

MD5:
a10967fa454534b620787c7ab97431c1

SHA-1:
d913a01e58e5f0dc9e7a7264452f9decee7f7e7c

SHA-256:
cafd38519be232424086b7fea6ad175154e12a3ec5f4684d6248cc50b956c310

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 7:39:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.BeijingAmazGameAgeInternetTechnologyCo.Service
16.2.15.17

File size:
61.7 KB (63,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mobogenie\mgassist.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 7:00:00 AM

Valid to:
6/16/2015 6:59:59 AM

Subject:
CN="Beijing AmazGame Age Internet Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22CF7DA7B76FC5C4E77225CFA1BDA497

File PE Metadata
Compilation timestamp:
1/21/2014 1:39:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:ZO+1ZvrMtrh1RTV9Ur5YrT7TIUSoOnkKWOYO+:g+n43TV9Ur2nX9OtuO+

Entry address:
0x53E2

Entry point:
E8, 99, 05, 00, 00, E9, 6C, FD, FF, FF, 8B, 00, 81, 38, 63, 73, 6D, E0, 74, 03, 33, C0, C3, E9, 1E, 06, 00, 00, 6A, 14, 68, 20, CE, 40, 00, E8, 96, 04, 00, 00, 83, 65, FC, 00, FF, 4D, 10, 78, 3A, 8B, 4D, 08, 2B, 4D, 0C, 89, 4D, 08, FF, 55, 14, EB, ED, 8B, 45, EC, 89, 45, E4, 8B, 45, E4, 8B, 00, 89, 45, E0, 8B, 45, E0, 81, 38, 63, 73, 6D, E0, 74, 0B, C7, 45, DC, 00, 00, 00, 00, 8B, 45, DC, C3, E8, D2, 05, 00, 00, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 8C, 04, 00, 00, C2, 10, 00, 6A, 0C, 68, 40, CE, 40...
 
[+]

Entropy:
4.7593

Code size:
33 KB (33,792 bytes)

Service
Display name:
MgAssist Service

Service name:
MgAssistService

Type:
Win32OwnProcess, InteractiveProcess


Remove mgassist.exe - Powered by Reason Core Security