MRNotif.exe

Mailocash

Rentabiliweb Europe

The executable MRNotif.exe has been detected as malware by 1 anti-virus scanner. While running, it connects to the Internet address rm-vip2.rtblw.com on port 80 using the HTTP protocol.
Publisher:
Rentabiliweb  (signed by Rentabiliweb Europe)

Product:
Mailocash

Description:
Mailorama client

Version:
1,3,8,11

MD5:
775b15c945f5957e237d0b552b724173

SHA-1:
7b72fa99858a365b8b34f5a602251a9b20e3dc14

SHA-256:
5b97e21e37892be175e0c167e0b659beafa18c506b2c29f9ce99e8966e9230f4

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/19/2024 10:44:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Optional.Rentabiliweb.Messanger.Meta (L)
16.2.9.9

File size:
9.2 MB (9,691,296 bytes)

Product version:
1,3,8,11

Copyright:
Rentabiliweb Copyright c 2010-2012

Original file name:
MRNotif.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mailocash\mrnotif.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/8/2011 1:00:00 AM

Valid to:
12/8/2012 12:59:59 AM

Subject:
CN=Rentabiliweb Europe, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Rentabiliweb Europe, L=Levallois, S=HAUTS DE SEINE, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0B3EC824CCA3728AF1A9240A43EE63A6

File PE Metadata
Compilation timestamp:
11/22/2012 6:53:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:nEgcqTEQgX34F1GfMlyamSAf3CN4T3DoF760h78Jsv6tWKFdu9Cf0+w+:EtqTEQWoFgfiJyCN4vCph78Jsv6tWKFt

Entry address:
0x4FE04D

Entry point:
E8, 00, CE, 00, 00, E9, 89, FE, FF, FF, B8, 97, B9, 90, 00, A3, 90, CA, CE, 00, C7, 05, 94, CA, CE, 00, 8D, B0, 90, 00, C7, 05, 98, CA, CE, 00, 41, B0, 90, 00, C7, 05, 9C, CA, CE, 00, 7A, B0, 90, 00, C7, 05, A0, CA, CE, 00, E3, AF, 90, 00, A3, A4, CA, CE, 00, C7, 05, A8, CA, CE, 00, 0F, B9, 90, 00, C7, 05, AC, CA, CE, 00, FF, AF, 90, 00, C7, 05, B0, CA, CE, 00, 61, AF, 90, 00, C7, 05, B4, CA, CE, 00, ED, AE, 90, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 11, D9, 00, 00, DB...
 
[+]

Code size:
6.3 MB (6,630,400 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to rm-vip2.rtblw.com  (80.89.119.200:80)

Remove MRNotif.exe - Powered by Reason Core Security