StreamClient.exe

Stream Client

Mombot

This is a setup program which is used to install the application. The file has been seen being downloaded from www.mombot.co.uk.
Publisher:
Mombot

Product:
Stream Client

Description:
StreamClient

Version:
3.1.5.2

MD5:
e6ecbc676fafa1d8556dd8c2682e56b0

SHA-1:
f0eeb80b63602c1e90b0946731a663db05041b62

SHA-256:
1ea254394bd10db382977c16f42462b60b49574a37a7f6bbe43ba42a9621dc2f

Scanner detections:
4 / 68

Status:
Clean  (4 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 10:29:25 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.TsCabk
1.3.0.4959

F-Prot
W32/QHost.C.gen
v6.4.7.1.166

Vba32 AntiVirus
suspected of Malware-Cryptor.FSP.gen
3.12.26.0

File size:
1.2 MB (1,259,008 bytes)

Product version:
3.1.5.2

Copyright:
(c) Mombot. All rights reserved.

Original file name:
StreamClient.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\streamclient.exe

File PE Metadata
Compilation timestamp:
5/8/2014 4:47:30 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:QaEIYjce49MzPUTnrnlcTLzlLbB2B9yqVrEsm6OSEXHlPL1JH:rEIYjlUf+TlL89BE5XFPL1J

Entry address:
0x20FF48

Entry point:
60, 9C, 88, 44, 24, 08, E8, 68, E1, FF, FF, 1A, 2B, 04, 85, E0, 03, 57, 2B, B1, DB, 59, DF, 01, 7B, D1, 17, 85, 2F, 91, BF, 59, FA, 88, 48, CE, F4, B0, 46, 74, 0A, 1C, 88, AA, 50, E6, F0, B1, 51, 7B, 10, F5, 45, 8A, 3E, 1D, 29, FF, D9, 69, 67, D7, CC, A7, 59, 0A, A9, 21, B7, B0, 0F, 91, 93, 3A, 35, C4, 18, 70, 80, 99, 35, 05, 4A, DE, 5B, AC, 83, 3C, 98, EA, E4, 9B, 5F, 94, CD, 7A, 24, E6, F5, 6E, B1, 7B, CA, 5D, 4E, 94, 3D, E8, 8A, EE, C9, AB, 6D, 9A, 5C, 60, 81, B0, 86, 46, D4, 80, 49, 69, 39, 3C, 5A, 20...
 
[+]

Entropy:
7.8245  (probably packed)

Code size:
24 KB (24,576 bytes)

The file StreamClient.exe has been seen being distributed by the following URL.

Scan StreamClient.exe - Powered by Reason Core Security