utilmegabrowse.exe

KnowledgeSlot

The application utilmegabrowse.exe by KnowledgeSlot has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Util Mega Browse”. While running, it connects to the Internet address static.vnpt.vn on port 80 using the HTTP protocol.
Publisher:
KnowledgeSlot  (signed and verified)

Version:
1.0.6283.34843

MD5:
7fde43a23034b1adf2ce5d0a8032db2f

SHA-1:
77e99032b4fb10764ab0d7954521931ab089315b

SHA-256:
2386266179a3f5abfe5b5c4a9844a1e86b425cf3f82531acfa62ffc472f1f276

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
7/7/2025 5:22:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.16.8

File size:
641.9 KB (657,320 bytes)

Product version:
1.0.6283.34843

Original file name:
MegaBrowse2017031603.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\mega browse\bin\utilmegabrowse.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
10/21/2016 4:00:00 AM

Valid to:
10/22/2017 3:59:59 AM

Subject:
CN=KnowledgeSlot, O=KnowledgeSlot, L=San Diego, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
571B5278123E0502FACCEABA06C95EC2

File PE Metadata
Compilation timestamp:
3/16/2017 7:21:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0xA056A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1734

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
633.5 KB (648,704 bytes)

Service
Display name:
Util Mega Browse

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to static.vnpt.vn  (113.171.230.119:80)

TCP (HTTP):

Remove utilmegabrowse.exe - Powered by Reason Core Security