mvob6.exe

OfferInstaller

The application mvob6.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from direct.downthat.com.
Product:
OfferInstaller

Version:
1.0.0.1

MD5:
9590dd3e9c6fd1462a65ae75aaffa166

SHA-1:
4252d35419ae3d12e61ead2a61323a31d989d097

Scanner detections:
22 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 6:03:58 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.578645
657

Agnitum Outpost
PUA.Agent
7.1.1

avast!
MSIL:Downloader-NG [PUP]
2014.9-150418

AVG
Downloader
2016.0.3135

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15418

Bitdefender
Gen:Variant.Kazy.578645
1.0.20.540

Comodo Security
ApplicUnwnt
21644

Emsisoft Anti-Malware
Gen:Variant.Kazy.578645
8.15.04.18.04

ESET NOD32
MSIL/Adware.Imali (variant)
9.11424

Fortinet FortiGate
Adware/Imali
4/18/2015

F-Secure
Gen:Variant.Kazy.578645
11.2015-18-04_7

G Data
Gen:Variant.Kazy.578645
15.4.25

IKARUS anti.virus
AdWare.MSIL.Imali
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.202.15482

Kaspersky
not-a-virus:AdWare.MSIL.Agent
14.0.0.2172

Malwarebytes
PUP.Optional.OfferInstaller.C
v2015.04.18.04

McAfee
Artemis!9590DD3E9C6F
5600.6791

MicroWorld eScan
Gen:Variant.Kazy.578645
16.0.0.324

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Offer Installer
4.98

Trend Micro House Call
TROJ_GEN.R072B01D115
7.2.108

VIPRE Antivirus
MSIL.Adware.Imali
39046

File size:
298 KB (305,152 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014

Original file name:
OfferInstaller_dotnet2.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\mvob6.exe

File PE Metadata
Compilation timestamp:
3/29/2015 2:34:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:MFZT8qbTR7SquD4L8vioH/X8i9DLnHWcefjVo8bS5VQW5BL:0ZwgVxGq86oH/MKvnolgnd

Entry address:
0x4B4EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9180

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
293.5 KB (300,544 bytes)

The file mvob6.exe has been seen being distributed by the following URL.

Remove mvob6.exe - Powered by Reason Core Security