utilmossnet.exe

Venturium

The application utilmossnet.exe by Venturium has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update MossNet”. While running, it connects to the Internet address zymail.zyxel.com.tw on port 80 using the HTTP protocol.
Publisher:
Venturium  (signed and verified)

Version:
1.0.6282.40241

MD5:
6df577a560b5a03cef3d003e7c5d620c

SHA-1:
5c8b7026624d5b33f312e7ac1a81e3a6aa7ce435

SHA-256:
1b80e38414c5b41cf1f0a990827f5065909605af91a638406e62296aa6a786c0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
8/8/2025 6:01:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.16.5

File size:
646.4 KB (661,920 bytes)

Product version:
1.0.6282.40241

Original file name:
MossNet2017031506.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\mossnet\bin\utilmossnet.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
10/21/2016 5:30:00 AM

Valid to:
10/22/2017 5:29:59 AM

Subject:
CN=Venturium, O=Venturium, L=San Diego, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
4383CEB82E18A96B6E6EBA7B768938CC

File PE Metadata
Compilation timestamp:
3/15/2017 11:51:31 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0xA16A6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1888

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
638 KB (653,312 bytes)

Service
Display name:
Update MossNet

Type:
Win32OwnProcess


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to zymail.zyxel.com.tw  (219.87.158.116:80)

Remove utilmossnet.exe - Powered by Reason Core Security