mobogenie.exe

The executable mobogenie.exe has been detected as malware by 32 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘6d89179801872f20a20c00195b2b6197’.
MD5:
c4a041b0c5e2023623dc1412d80b269e

SHA-1:
68ce54854a3ca4177f4da476e07385fb617c065b

SHA-256:
0dc41a009717034c493e85e9323d453a6fa8716d56b900a13749273b5ef4452d

Scanner detections:
32 / 68

Status:
Malware

Analysis date:
5/8/2024 12:28:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDZ.24293
978

AhnLab V3 Security
Backdoor/Win32.Bladabindi
14.06.02

Avira AntiVirus
BDS/Bladabindi.uppj
7.11.152.176

avast!
MSIL:Agent-BKA [Trj]
140531-1

AVG
Could be a Trojan horse PSW.ILUSpy
2014.0.3955

Bitdefender
Trojan.GenericKDZ.24293
1.0.20.765

Comodo Security
Backdoor.MSIL.Bladabindi.A
18405

Dr.Web
Trojan.DownLoader10.63222
9.0.1.05190

Emsisoft Anti-Malware
Trojan.GenericKDZ.24293
8.14.06.02.11

ESET NOD32
MSIL/Bladabindi.BH trojan
7.0.302.0

Fortinet FortiGate
MSIL/Bladabindi.Q!tr
6/2/2014

F-Secure
Trojan.GenericKDZ.24293
11.2014-02-06_2

G Data
Trojan.GenericKDZ.24293
14.6.24

IKARUS anti.virus
Backdoor.MSIL
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.178.12278

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3773

Malwarebytes
Trojan.MSIL
v2014.06.02.11

McAfee
BackDoor-FBIB!C4A041B0C5E2
5600.7112

Microsoft Security Essentials
Threat.Undefined
1.175.1108.0

MicroWorld eScan
Trojan.GenericKDZ.24293
15.0.0.459

NANO AntiVirus
Trojan.Win32.DownLoader10.cvaozm
0.28.0.60100

Norman
Bladabindi.JQ
11.20140602

nProtect
Trojan.GenericKDZ.24293
14.06.02.01

Quick Heal
Backdoor.Bladabindi.AL3
6.14.14.00

Sophos
Mal/Bbindi-B
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Bladabindi
10568

Total Defense
Win32/DotNetDl.A!generic
37.0.10974

Trend Micro House Call
BKDR_BLBINDI.SMN
7.2.153

Trend Micro
BKDR_BLBINDI.SMN
10.465.02

Vba32 AntiVirus
Trojan.MSIL.Disfa
3.12.26.0

VIPRE Antivirus
Threat.4799966
29800

Zillya! Antivirus
Trojan.Disfa.Win32.10564
2.0.0.1809

File size:
23.5 KB (24,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\mobogenie.exe

File PE Metadata
Compilation timestamp:
5/3/2014 3:33:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:W7MKFYuEEhERvoBG16Xuy0MHNw6Tg1Y+75JTFmRvR6JZlbw8hqIusZzZgM:WQW4V6+yDRpcnu2

Entry address:
0x748E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5280

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
6d89179801872f20a20c00195b2b6197

Command:
"C:\users\{user}\appdata\local\temp\mobogenie.exe"..


Remove mobogenie.exe - Powered by Reason Core Security