girls-mobile-data.exe

Girls Mobile Data

The executable girls-mobile-data.exe, “Girls Mobile Data 1.5.8 Installation ” has been detected as malware by 5 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from nl2.ero-advertising.com and multiple other hosts.
Publisher:
Girls Mobile Data

Description:
Girls Mobile Data 1.5.8 Installation

Version:
1.5.8

MD5:
d0539d761828a3fc3c48be0d4b4df412

SHA-1:
6c50b75cffec5629f6fefbd3c5431228c6abdbd0

SHA-256:
731833ed83764f18afbaa104ec4cb6a24c1b12861fb283aae5faa52874f7fa9c

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/26/2024 4:45:11 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Heur.SMHeist.3
5819428

Avira AntiVirus
W32/Slugin.A
7.11.30.172

avast!
Win32:Evo-gen [Susp]
160112-0

Emsisoft Anti-Malware
Gen:Heur.SMHeist
10.0.0.5366

Norman
Gen:Heur.SMHeist.3
11.01.2016 17:30:26

File size:
195.8 KB (200,458 bytes)

Copyright:
Girls Mobile Data

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\girls-mobile-data.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:zZABbWqsE/Ao+mv8Qv0LVmwq4FU0fNoy6XmOwG:lANwRo+mv8QD4+0V16XVH

Entry address:
0x25468

Entry point:
55, 8B, EC, 83, C4, F0, B8, 88, 53, 42, 00, E8, 24, F2, FD, FF, B8, C8, 54, 42, 00, E8, 2A, 1C, FE, FF, 8B, 15, 40, 88, 42, 00, 89, 02, 8B, 15, 40, 88, 42, 00, 8B, 12, A1, 48, 88, 42, 00, E8, E4, D3, FF, FF, 8B, 15, 40, 88, 42, 00, 8B, 12, A1, DC, 87, 42, 00, E8, 7A, 64, FF, FF, A1, 40, 88, 42, 00, E8, AC, 4E, FE, FF, E8, DF, E0, FD, FF, 00, 00, 00, FF, FF, FF, FF, 01, 00, 00, 00, 2A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
145.5 KB (148,992 bytes)

The file girls-mobile-data.exe has been seen being distributed by the following 50 URLs.

http://nl2.ero-advertising.com/popads/logview.php?spaceid=313460&siteid=93092&xref=ddjEGTdnddChCq2X4YgPMJyrZBLC CiX8CfbRquZt0N6OeUvBVwthzQdqXfIsyrHWQflQjfBrf7GiodOpYVBW45RJ36LSp4ar8dNjjO5Lr9wVvBS2Otogm6KoxumGPX7LclDLD4fZcCMtXJrLUhHUv aH/kcgEF/dX/LX3uMuih2v5cwD4qSLnIn7AqOkHXjYt8IOQNeMG5Za9OAuAuun hoLAeu0DmwlU6WyDC2qA7 8Jt/aK SVvd14BFWToDAYhJcSNbbgJ/.../LbMcVUCDZPp2MS44XboqzA74IfJnhbZx8new8EJhcdx1AgCn2Upb6QHCPqR3vuLr7wXmEfgTEVd2PIawnTt7c6wRakCDMG7p9smOtLjXGfMw==

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=988741171476&m=-1,-1,0,0,0,-1,-1,2,0,6,-1,-1,1280,899,1280,984&iuid=1527166154&pl=!7sOsX3gRJUfVqehpvNBCpagWJ7JAndRNirNO02dnWbZBvmgagbfagjdhdfpfGO6it0J/i9eq57NuKkf/ybaGXTSbbg1rl3iEBW721QmbIUT9ysjxB/UiWPUKDhYCZymZO6BMcScSUnviBBLUKlQqVEAB2uk1QF4rZ9olk43HalQPPgmkQWeH72 cQnLka7p/.../BgGSp5drX1CoKyuT3BlAWdDJ10Rtmk37VhmnKQIaZV5pbhltXdc9MRhJIe6U9gn0jny2eAtHHEXcQ==&ac=4482770350872135&jsv=017

http://pops.ero-advertising.com/popads/logview.php?spaceid=2049688&siteid=106723&xref=J0snDq7Uj4ys3MH0vMMH1abt5IBLdPfbLNdxn0XZS/ZSI1r8fm9q9 xt1/HXTu2IfOk2AbPZFxb9tjCR98i7Ft3BCUIwEmT3C/wTwRLLwk7pgonQjN7JRuBy35FDf/J9lEm2JF9EbJXXTCV0PeYkviMEqJdE2AdYYiSshTNUZnx5K0V 6TZCXjLKbIpnHcwN6lznp4LHVSMxqZ7MPVN66RnmbFZeyaEo2gn5NF4v1GWK 46C/ag2uhnJbKVRmPeVY3NJLt BGaHVAT//.../dFvAvGzJX8QpIW jb9HeTT04th398TIxcq7lh7Mcq1SDIxCY4tc5e6 M=

http://nl2.ero-advertising.com/popads/logview.php?spaceid=2033131&siteid=85607&xref=b3XyngQ0WjYt22eowEg85aUyCLwCZVy7IwBJlxKkwz cNPC05WiQGmTsflYVjpiOvg1082rsGe3/2B2OgAIgBWTfwNOxLiJR4cd4b9bkHNIYVBiUN1ba9NE6UbxMy5XMGz6r2yZbzOJEF76EcyCnOCVrSTwpzj5AdyCp0jPeWdCRNlj22K/8gZ2p2C vJ26Br9wCyva2e tJK/us/.../9apLjIfHhXvgw9A64IWfwqO6 VGZfdoIU4o8jYW5kPlo7zEerg==

http://pops.ero-advertising.com/popads/logview.php?spaceid=1978995&siteid=83919&xref=j8iYtFuUVjgMIQ6odQ/lYxXpgxWrCZYr1p43J4FonR1l1 Hk8gfzH5oXx84w/QI4Wui1g8amQctelpV9 Nq 3itmbkhxVDqkUZWZEjTr5nKYRdnid/uNxqwO6I6QLwmXiLQ9lnQW49ckjg3nq0FZh47duxOSTztspbMvqmnIegX3ndAMwemZsA85lJVJ5xsVhAot955Ekzcn9v7QD1Ypeqi3c Pk2o6iVgOtHR8KKd66KLvg/.../8IetBXV QNyPf5PVTH0LivL81B1uJ00FTw0hVAWnpwRxyIM1wc=

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=987228074232&m=825,572,78,1170,315,839,604,4,3,1,-1,-1,1366,667,1366,728&iuid=6046951401&pl=!J 31pfbd2Qbd3hIWWbS036/93xsB/.../mzdXHh9MYC57F0CAQT9 4iaIWAFZWvJPfHAlUB1m8CWN0DNnlOZfPYqHf47K0Akm2AauRTsKIezLkeY2Lsl&ac=8324834431309582&jsv=017

http://pops.ero-advertising.com/popads/logview.php?spaceid=362978&siteid=83919&xref=E8ZaEG6DrJoBb/HHSDWz2OVWlEJi5z4X2l6lpxrV wmJFau1h8p6jJPZYhLplvcdOkAoI/r 2f9tRmhAyay16/G7NDKAacUSbn8 6FY8jugW1GeWoaV4SLGwY9QdtXybhOrLUf6YobBW0kEli4v9fIG ITx DUzh45qDjx5tD8hRIZmJTX75ZSykllR2rTzVWyww0EDt3NtbCOtEiAgJJhYO/.../DNeHCfMLFFJTjD8N47otVovW JIjnD km4zsOLM=

http://pops.ero-advertising.com/popads/logview.php?spaceid=2001634&siteid=83919&xref=G/.../Heuk15uI4xHcWj2l0eXVcoxN7VOQygmChEczWBejpMfZfQ3rT73gn07Ypt36Xljd0LkgsUlS ncFk2uOiMS3FxnTTUK0hyLA81WMP6CjD4SgwTwXgjHfdjsBmUqOBqq6dfJL1WwmZG7eZ0w4R4YVBHrJNvxPl8ui WcOU moSjznADkHotjDQBRJtBnZjA5gXYYgihJPfrAdVmCpUhzvXV71Hm916tumkmusNvxiR1dBVjDffzP0wBLj6AYxiuFKwqMXk2HPOBF5Z2tjs26Zga9TjXYxoLlOTcJvSADK05nz2aNWbtfNdPNMxGf20WKQ7 ncEbMs=

http://pops.ero-advertising.com/popads/logview.php?spaceid=1978999&siteid=83919&xref=QgOfxOE4VJXM1YZqMQWx0oOaRXR7KnbDitz BFh BUKStaWCqqX YSrOEdz8WnqGi18kZ7Dnze3vMGRk2Vi4e38fiArbfbCqbLtQUkVxZ4wjhnfOZ4wx ktZ5x9CMZyD8k4Gq6HcLXF7NoeHGOsaKO0rhSKzIwvNz3vCCBqqj2O5xsguK3TkoD46JDrGGEynTtyfIjuSohgSO9L/Did3fRLUJmSkQVu1Iw9sB57FLZjQyvIh UrC9uXEtE9oiVIytWArz3wt88CASRg1J knn1D6K0DdexKFaMIe4fk3c PTnzpN AaqH6vJHZOcIjKo8OijNQX6pCnB/.../cgC7MA35X UnUdiqj2Qdyg2U=

http://pops.ero-advertising.com/popads/logview.php?spaceid=362978&siteid=83919&xref=x48IPzWN25koejiHjWZhH4xQENuIweuZuReenJFY05vQB6zmo8juFuFvdy/11zJw9MmgtJYi9nNeiX /ArT9rGY9m3yc0z/jm0fpP16g7LuXIWn7WIsWkpwCgfyh9FqArQgxv6wnQrSZcqCHKmcZgh0Zv6ljdi ED5WtAwKOjlijgALrBQDGkwy9HAd /.../522 cuM5v07 Rj8lVk6kdUhZ9mH57IEj2itJFgvUGAMS3m0DUYSc44jl8VJrqgRrecvYMstMXDoKKuZw1kn0RqACJ62xDFsFcYSnXED0BJsPz7I1VUBh pk=

http://pops.ero-advertising.com/popads/logview.php?spaceid=362978&siteid=83919&xref=s49BWZwP6rWNya kEgPijmrOaOO3um7GTaNGa/bapzDQk3 4qky46C Zmx9NxsIvSd/xybBbkUVGABPT b8CS9KzSFyVKW/rOce3tFVDHtmv6Sck0k tsE55v1FB4jT/hZZj4pabD63Ky5ipX3qHo3JacwVde TQSq/mFjhen9Cs2X0SxB/3jjKTwslFOdpG3KMoq26u2/fYqMG19mx6c3YpXr0WodwdqjL4hy6drBEdqtisADl1MWGYzgLeNVc8Ksoc0htxv5R7ofhBe1/M/.../JkFyhhX8elxITcLtOHmkghxzVVQc X8mXSUgkcJ0f kEgsdgoIc03K9RiWX8g3 EQvd7Ji0xXSA=

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=989291100024&m=-1,-1,0,0,0,-1,-1,10,0,2,-3,26,1280,1024,1280,962&iuid=9736668853&pl=!ooFIoC4JnAeSYshgr0UsPvJjty0/4xAwBH4S k9uoU TCy0qAJ1DgXMmofwed65t8yQKZK7ar80qYmCGE5Ke wP 7TFabC9iCVRaW3toLDGHeuCuuU5/r0/67KqBKOq4SHZR3KcSRWagmeN kuWMnXUs5L4OuMXdaRO5H hOmF4yte/Ui/Eb5iJPbw27ycTIpzKZ5ZyM13q Los7/wR0Yg4CfUtm1vWimx0dafIuMS6gV55zZrmd5owvJZ1a2u2xITeAA8IGcONwetn0ugUQhmbhF3tHx3iLlxQya1un29UNTzuwTF08tpDxsw4hcxqVfAEXTJtmTHg2Ufv/45RSIBLqUePnAr3ELwiTBE5ebWlV/.../PpuZpvvzr63BaXhiIQdmi6JbSnTkWhNjpMoeleVXb9F2pcSxsz4T5BklR9hS0kxyCFfE1GL6qvp3RAFIVzQodui6vnRZyRw==&ac=46850372709761&jsv=017

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=989146722708&m=388,599,11,20,3,387,579,1,0,7,-1,-1,1024,667,1024,728&iuid=7627012301&pl=!uzbQUKV/X/7PImnKZmgLO1 DLWj76bI 0WRDlp8fMj6zdZqKfRKrWCcQpNxSm/Rj8Smh0SRb8DgqPWCwgad3ldJcc 6Q1Dfn3jGEsv31dEM6fARkou9zMiHTJ7lZYnQhJb/uS8CjES4OpxtYZv KOatPfOjgRmO8iNmmFbe9FrRn0S8wdMvl9NzS/K7PK9XIhGerVeLen8TCncfRKoazqT/z48aFfZkSBmZPmmcAhb/BDvvic/vtcEvnQVGjnBNJFL8qhuVuzm2Lr/.../KvzpP 6uEbSFo=&ac=3276411419773757&jsv=017

http://nl2.ero-advertising.com/popads/logview.php?spaceid=2005875&siteid=96912&xref=lGApzLpX/.../lSTcUc4azJ1eiHwe921thznSjapdHETs3qWujcC7CCcALsCBF62K0MQDeSthboBzKJ0kS0C0Ll9oXoq60yvYbF1avYyPErRBtdx7B3Ho8aKNjazmSQvx5F4K0eZQ78i7R3BJjW5v3boSI3zHXd2F7A==

http://nl2.ero-advertising.com/popads/logview.php?spaceid=324971&siteid=77180&xref=KvXvPhQ5wdE3MkIHyxEkAUBkihsbtfIUOZ6KO6qRRBV7ymkmV2g5sJ7LUcVgf0h3H eBYuoPqi5G7heslpvWfCHtlVGcQWSd7FBjDdm/Pje701AaxeOLvDxI/RIL/Wb5yw TRYUPR96bMd6JblbS1JLq6eIzqgrnacyQ8PUqz20M7MSVImFhQSZWwA1EHwz5EWNNg84mC8fhfzPty1vXVr/iQYB8EU3MPJ9DnCtPhJCClegMYpLaF68kS54HTIp5N47mRo6EB7OLB4tmbXa/ERH7zO4JlpZhL0j8PXYl/jJsJ1PiuXqjDojfqtidmtj3NkxcNLWzvN99Wg0eZHt5hUpJwHKlztZ60BKOY0hCn6AAQBNK2xE81mMrHEn40E0pfosG4 vBnhhAPyF58BqM0CYiBnI6XVeDRLIS/ctDpOgTT8Pa3bgjLs4XyUcZi/.../7T9qXLR8xqcs4cY5g==

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=988786351404&m=-1,-1,0,0,0,-1,-1,1,0,-1,-1,-1,1280,923,1280,984&iuid=9811161563&pl=!oNH5qH3E7RMHiTbI23YNxi/P5qNbKvEC6z3QDnRgqaNLQU7e hEQusSKX1hipWpOcgZXZ8lDLaOZyGkD8famkJybt5C54EPd2AbAl k6rU1Sxa6wJh/.../BziOUL3KeGM7lEiHAjmP Jhe1Mm2VayE0cIWLxvqPCzqJxlTjnI4P40Nrh7IxPO4in5PlwXexyrngr5FcmYk8BkDysEvQPVjEBnFouPtPFzLWiYKu9&ac=6849364466345547&jsv=017

http://serve.popads.net/popOut.php?c=10000000000&wact=&a=987271328448&m=-1,-1,0,0,0,-1,-1,2,0,2,-1,-1,1240,923,1280,984&iuid=4538123813&pl=!kaE7vsx snDjk1cHaHWnCW320kVA8icZd1bzKlvpwEgRujWE/R9GUG95nn 7vix8i7MA9eBgP7haXyP3LxqQhtSbUngArqVO5nieZxc 56li3PvFo3L24KHblR37PAJlOSdFbfnvJYf/a7nKWLABkhRl IBiS8tzxWIrU5U6Rm7dKr0MnTReD/.../cGhQkfDfoODXDDCibw9&ac=4268015846038219&jsv=017

http://pops.ero-advertising.com/popads/logview.php?spaceid=362978&siteid=83919&xref=mmq0MbBwTZ1A0CUOGJtz43Y56N3BjSOwhsTjTvUuT3noImyUGFb1AMkgG5VnblT3 4r nqjQ/.../s8Guvx8sw9avg9inm 6SqdluPuurJt6tagqWDxzrTo25CwLzRwiqfK9ZeyksSH7qAeAUXDVcu5A9VTWJajdWBY61hL3vWxueYQZexECCea0eJoATuF0WDwDH32isInsmicOZvBYKLpVHbwQ GhvlMQ1kURwciojRlkTgMMOfru wsgC7 n6QGApmg2xIe8T2YhJRTTsWFvekhl4K51g3KPx3KBhg=

http://pops.ero-advertising.com/popads/logview.php?spaceid=362978&siteid=83919&xref=mvPn3BXwPr8/T CAX91vjYC8C5QVP/oMRIYFDcWem0eqBK/uB9hKFH CQwbSc1dt1uMdICtMz9HMtpqeVg8UUy/eumVVXchWqazaFaXg/Ilu5XUPtz7CA5xXpaMJ31vAXz2236L6eYm7F 5 fBAT U0NttwwWyJI8O3sEGLPF3c8Mo146Lt/ldTfY6cxfqRL618Hsyiayi9YdYPn8jEFMTgtYOWTSGCdelpBKEDZgtowO YZLjoET3MbDa4dR7zh6/.../lBU oyxpxiOfFocXi FhtKHnXSnZ3BF3WZv0nkJKQ0OMHHNL7dTWls QK3Q4vQ6VI=

Latest 30 of 210 download URLs

Remove girls-mobile-data.exe - Powered by Reason Core Security