mpxbox.EXE

MPXBox 응용 프로그램

MarkAny Inc.

The executable mpxbox.EXE, “MPXBox MFC 응용 프로그램” has been detected as malware by 36 anti-virus scanners.
Publisher:
Marktek Inc.  (signed by MarkAny Inc.)

Product:
MPXBox 응용 프로그램

Description:
MPXBox MFC 응용 프로그램

Version:
1, 2, 0, 2

MD5:
d4bf65951baf67563572ef6ff05b6788

SHA-1:
b017ff1c6d78e72449b8ef8b43faeca4346105bd

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/25/2024 1:38:15 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Win32.Slugin.A
7.1.1

AhnLab V3 Security
Win32/Slugin
2013.02.22

Avira AntiVirus
W32/Slugin.A
7.11.62.72

avast!
Win32:Patched-HO [Trj]
2014.9-160210

AVG
Win32/Slugin.A
2017.0.2838

Baidu Antivirus
Virus.Win32.Patched.$dj
4.0.3.16210

Bitdefender
Win32.SlugIn.A
1.0.20.205

Bkav FE
W32.OlayFara.PE
1.3.0.6267

Clam AntiVirus
Trojan.Spy-59563
0.98/18155

Comodo Security
TrojWare.Win32.Patched.P
15333

Dr.Web
Win32.Wplugin.1
9.0.1.041

Emsisoft Anti-Malware
Win32.SlugIn
8.16.02.10.11

ESET NOD32
Win32/Slugin
10.8038

Fortinet FortiGate
W32/Wplug.A
2/10/2016

F-Prot
W32/Slugin.B
v6.4.6.5.141

F-Secure
Win32.SlugIn.A
11.2016-10-02_4

G Data
Win32.SlugIn
16.2.22

IKARUS anti.virus
Trojan.Win32.Patched
t3scan.2.0.0.0

K7 AntiVirus
Trojan
13.160.8245

Kaspersky
Trojan.Win32.Patched
14.0.0.683

McAfee
W32/Wplugin
5600.6494

Microsoft Security Essentials
Virus:Win32/Slugin.A
1.163.1557.0

MicroWorld eScan
Win32.SlugIn.A
17.0.0.123

NANO AntiVirus
Trojan.Win32.Wplugin.edowv
0.22.8.50637

Norman
Agent.VDAZ
11.20160210

nProtect
Win32.SlugIn.A
13.02.21.02

Panda Antivirus
W32/Wplugin.A
16.02.10.11

Quick Heal
W32.Slugin.A
2.16.12.00

Rising Antivirus
Win32.Agent.ik
23.00.65.16208

Sophos
W32/Slugin-A
4.86

Total Defense
Win32/Slugin.A
37.0.10305

Trend Micro House Call
PE_WPLUG.A
7.2.41

Trend Micro
PE_WPLUG.A
10.465.10

Vba32 AntiVirus
Virus.Slugin.28805
3.12.20.2

VIPRE Antivirus
Virus.Win32.Slugin.a
15680

ViRobot
Win32.Patched.N
2011.4.7.4223

File size:
484.1 KB (495,747 bytes)

Product version:
1, 2, 0, 2

Copyright:
Copyright (C) 2004 Marktek Inc.

Trademarks:
XSync - Marktek Inc.

Original file name:
mpxbox.EXE

File type:
Executable application (Win32 EXE)

Language:
Korean

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\contentsafer\mpxbox.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/2/2007 7:00:00 AM

Valid to:
2/3/2008 6:59:59 AM

Subject:
CN=MarkAny Inc., OU=Software Development Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=MarkAny Inc., L=Jung-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
31BFC0616F27F7414E146840E38B22AE

File PE Metadata
Compilation timestamp:
9/29/2007 2:37:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:3Z/6hLaWxukhOecfgiBTLBLCGf1E0oUVvnqZ4zytbLq:N6hLaWskhOFfgaTJCM13o4zk2

Entry address:
0x12012

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Entropy:
6.2614

Packer / compiler:
ASPack v1.08.04

Code size:
188 KB (192,512 bytes)

Remove mpxbox.EXE - Powered by Reason Core Security