downloader.exe

Beijing AmazGame Age Internet Technology Co., Ltd.

The application downloader.exe by Beijing AmazGame Age Internet Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:

MD5:
adcc50f73461c6d86ab045324cd8ed8d

SHA-1:
dc8d28cc552a40e8efea8aad694b35fea8e923a8

SHA-256:
8fad6fdbf9abe2933930de3a938cffc2d43ed57028765f3b2f1ba2e3bb696566

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/23/2024 10:33:41 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.BeijingA
17.3.15.2

File size:
261.7 KB (267,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mobogenie3\downloader.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/16/2012 2:00:00 AM

Valid to:
6/16/2015 1:59:59 AM

Subject:
CN="Beijing AmazGame Age Internet Technology Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Beijing AmazGame Age Internet Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22CF7DA7B76FC5C4E77225CFA1BDA497

File PE Metadata
Compilation timestamp:
4/30/2015 8:15:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

Entry address:
0x19726

Entry point:
E8, AF, 90, 00, 00, E9, 95, FE, FF, FF, E8, 95, 91, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 97, 91, 00, 00, 59, F6, 05, E4, C4, 43, 00, 02, 74, 11, 6A, 01, 68, 15, 00, 00, 40, 6A, 03, E8, DE, 3A, 00, 00, 83, C4, 0C, 6A, 03, E8, 97, 5A, 00, 00, CC, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, A1, E4, C4, 43, 00, 8B, 55, 08, 23, 55, 0C, F7, D1, 23, C8, 0B, CA, 89, 0D, E4, C4, 43, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, 3D, 68, ED, 43, 00, 00, 0F, 84, ED, 92, 00, 00, 83, EC, 08, 0F, AE, 5C, 24, 04, 8B...
 
[+]

Entropy:
6.4980

Code size:
196 KB (200,704 bytes)

Remove downloader.exe - Powered by Reason Core Security