MediaStreamingAgent.exe

MediaStreamingAgent

Boxore OU

The application MediaStreamingAgent.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. While running, it connects to the Internet address ns04.hiwit.net on port 80 using the HTTP protocol.
Publisher:
Boxore OU

Product:
MediaStreamingAgent

Version:
6, 2, 0, 0

MD5:
ecea24852601893b106129417401c1d7

SHA-1:
53d59a81299eaf2adfdc0b503049316be4bfe8c5

SHA-256:
e9cd516576687d4fe07e0d2bd25e7792b4badd918d78bec8c2f7d9427decf3c3

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/5/2025 2:03:20 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic_c.DKH.dropper
2016.0.2946

Dr.Web
Adware.Boxore.25
9.0.1.0297

Reason Heuristics
PUP.Boxore.BoxoreOU.Meta (M)
15.10.24.18

File size:
1.1 MB (1,204,736 bytes)

Product version:
6, 2, 0, 0

Original file name:
MediaStreamingAgent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

File PE Metadata
Compilation timestamp:
10/19/2015 12:27:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:PQoeMRBlxi38NZzB6XiDWK+7Orn9Nfzm1xvoMrbWE0jBj:ri38N6fKSgvm1xvoMr6

Entry address:
0xEE000

Entry point:
E9, 5C, 75, F8, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C3, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
784 KB (802,816 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ns04.hiwit.net  (194.150.236.156:80)

Remove MediaStreamingAgent.exe - Powered by Reason Core Security