MediaStreamingAgent.exe

MediaStreamingAgent

Boxore OU

The application MediaStreamingAgent.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘MediaStreamingAgent’. While running, it connects to the Internet address ns04.hiwit.net on port 80 using the HTTP protocol.
Publisher:
Boxore OU

Product:
MediaStreamingAgent

Version:
6, 1, 0, 0

MD5:
310cafa58e1080e803c3782d5d8d184f

SHA-1:
290946820bce0f9a8d8519c39126eb849bccc2a1

SHA-256:
b6971d28f13644a7223fb55b3e3dfe7eef1981716386058e90232e74b967a4bd

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/5/2025 2:04:20 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Boxore.BoxoreOU.Meta (M)
15.9.25.19

File size:
1.1 MB (1,187,328 bytes)

Product version:
6, 1, 0, 0

Original file name:
MediaStreamingAgent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mediastreamingagent\mediastreamingagent\mediastreamingagent.exe

File PE Metadata
Compilation timestamp:
9/22/2015 4:22:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:wLRKQ/ALyhSlm2Ei1TtJWuwQZ8rbrJH6lldi1X5QoxSIHlCjBjlnsq:FyhSyi1TcQgCldKX5Qox/ynsq

Entry address:
0xEA000

Entry point:
E9, 8C, 7B, F8, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
765.5 KB (783,872 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MediaStreamingAgent

Command:
C:\Program Files\mediastreamingagent\mediastreamingagent\mediastreamingagent.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ns04.hiwit.net  (194.150.236.156:80)

Remove MediaStreamingAgent.exe - Powered by Reason Core Security