winmx_music_487l.exe

WinMX Music

Prospera Software, Inc.

The application winmx_music_487l.exe by Prospera Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from aresgalaxyonline.s3.amazonaws.com.
Publisher:
AresGalaxyOnline LLC  (signed by Prospera Software, Inc.)

Product:
WinMX Music

Version:
6.3.0.0

MD5:
edf2718ea8c084f4601e024e14beeb2d

SHA-1:
fc843cd038b7f07165815683d4bc22b9347accea

SHA-256:
8ceda918d9fd8ffae0a6ed0bfbacf2c550164748d8f658806f7376dc3cd171c3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/29/2024 6:26:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Prospera.Installer (M)
16.5.8.8

File size:
4.3 MB (4,536,328 bytes)

Copyright:
� AresGalaxyOnline LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\winmx_music_487l.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/24/2015 8:00:00 PM

Valid to:
5/24/2016 7:59:59 PM

Subject:
CN="Prospera Software, Inc.", O="Prospera Software, Inc.", POBox=30024, STREET=4539 Arbor Crest Place, L=Suwanee, S=Georgia, PostalCode=30024, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
19A1AE80173FC78EF95D67C4BB75F591

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:XoN4bvHfSTwTueOlKDpKHTwkfhj6jVPC05qUcuRLgZkjPcSF3Huor4a80uWQ8:YebnIwTZxDoUkf0jVPfgZkjJHbuWf

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9968

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file winmx_music_487l.exe has been seen being distributed by the following URL.

Remove winmx_music_487l.exe - Powered by Reason Core Security