mobogeniemini_1002_10006.exe

The executable mobogeniemini_1002_10006.exe has been detected as malware by 10 anti-virus scanners. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from upload.mobogenie.com.
MD5:
ea4bb282460ac7982832351bbcc703e4

SHA-1:
0a68be98725b47894d3941efbcd9704358a26f3e

SHA-256:
401f7f79553055e49a94e3208d26faa95ddc4d099be10cf382088d204b47d8ea

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 2:35:12 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160215-2

AVG
Win32/Sality
2015.0.4530

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5735

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.7429.0

Norman
Win32.Sality.3
19.02.2016 10:08:15

File size:
842.7 KB (862,920 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\mobogeniemini_1002_10006.exe

File PE Metadata
Compilation timestamp:
2/25/2012 12:19:59 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:VrnuGG0MXPHGbzsk5M3oDuAGXjQ8JHmGAoXjuG:duvgeLX08JGGnXaG

Entry address:
0x39E3

Entry point:
0F, BF, D7, 75, 03, 0F, CD, 49, 78, 02, 8A, EE, F6, D3, 70, 03, 0F, AF, F6, 03, C2, 8B, C9, 89, F3, 24, 0C, F6, C1, 9B, E8, 10, 00, 00, 00, 18, FE, 0F, AF, DB, 88, FE, 8B, FB, 46, F6, C1, 05, 2B, C7, 43, C6, C7, F4, F6, C6, 53, 38, F3, 84, EB, 52, 89, EA, 5A, 8D, 2A, C6, C5, D1, 69, FE, A2, 76, C0, 90, 03, C5, 81, FD, EA, 03, 00, 00, 71, 02, 1B, D8, 88, EC, 0B, CB, 81, E2, 45, 9E, 04, A6, 78, 08, 8D, 2D, 2F, EF, F6, 82, 09, C5, BE, C2, 06, 00, 00, 81, F6, 69, 04, 00, 00, 8B, FB, 8D, 1E, 85, C7, 81, F3, D9...
 
[+]

Entropy:
7.4798

Code size:
28 KB (28,672 bytes)

The file mobogeniemini_1002_10006.exe has been seen being distributed by the following URL.

Remove mobogeniemini_1002_10006.exe - Powered by Reason Core Security