moborobo(moborobo_en_official).exe

MoboRobo

Moborobo Inc.

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
MoboRobo Inc.   (signed by Moborobo Inc.)

Product:
MoboRobo

Version:
2.1.7.215

MD5:
97924d9bbcb2b66f535ec715fe913da5

SHA-1:
10eb5ddcea0b06edc53dfcb471306b3e0df07616

SHA-256:
db351c09e9ee76556f01b28c7f29e4e13bb6c7208e5f3eacfbb351ae002c6bca

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 10:34:52 AM UTC  (today)

File size:
23.6 MB (24,709,848 bytes)

Product version:
2.1.7.215

Copyright:
MoboRobo Inc.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/20/2012 12:00:00 AM

Valid to:
1/19/2015 11:59:59 PM

Subject:
CN=Moborobo Inc., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Moborobo Inc., L=Diamond Bar, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0231D10DAC1BCB58D969F8A97E97D99C

File PE Metadata
Compilation timestamp:
3/17/2011 10:22:54 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:Y59ulPy3yBjEd35rFUySWg7XtKCSzHlhfPDbTIyx8dNf/lH0FANVVJ/zKsicGUi:Y59uRy3YjEBiBX56ff5i3lHMAzri

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file moborobo(moborobo_en_official).exe has been seen being distributed by the following 8 URLs.

https://dw.uptodown.com/dwn/j2EPETDU6XjNo-44PPbmFi3qZ4UKCzTdMArjMbeP6N3QGoV9L5-8zbijIok_DoLYvOcmEt_ExWbhxvDU3ZEH_uf7jpyVUgnawJ1Ey8GGRMx4yd6ja6LXlVLOkVuyXq9V/s15KQnmZ8owB5Epkn3KXDsE11lYgo3zzXIx9HO3ilt_5nUHdf93_l4UDtD_AMv5aDAivzco89SM5YpNdfNyw1stYrGxLUGBPhos_b-ZM4BEO3BQ8frwi_tc6hLzxmky8/HqiaHxPkTd31Syf0dUCzftbvPFJmMc3yC-Ti-S7D_TCSd45SdLT0HROP5stpcTKyEu2gNPNv6drjo9nRbZBW2s8IcRrTpFV6nI5XyxxaLD168DHYFntKLaqWvMTypKXz/.../

https://dw.uptodown.com/dwn/2G7m0LxabrQBi5UhOEvslhVLYC6X7eENEnamujOaqLumwWJPKigzrmTuliAANLim1oOgdz1_wQR5FJgHAQmFAUVAsZM5ejrWnvDlOlOZnKOV1haFL6JAmYPSO0Oc_kPZ/eUdiEzwZ1bP1KjS-CzQp8ZLBoCCPwPD1SxbHzmz0MsE5bH2OLFNZ9HS_bwnH2SGqCv3AWJS045j7Y5XXQa2tkdwMqqCj1n3uZaMLiQFLSP-PvGziMCuRo9nZm6dtgy6x/Quy25w6rRrSf7qsVYmycMicDS8x57Dye5ar9OvIkrfEAj_45MggQ-3AMKdpFmSlOv8vv2Evu75TSFuV2qtNUqZYLQvCa75VhfkDDZtYF9yfX20uSyi1lfGA-XQk4hU6C/.../

https://dw.uptodown.com/dwn/BcI1n2CvJ--qaOstlitvw_PSTRhgrj0ZOqwSL8e7kKL9MfvZe3FGljSj31yTmeUG8U229DqMTmzUybzuyzDZrzRSjjaDixKiY0IK5U0HpGD3qI2xWl_9MV8ouR0QSB0V/YvGZUnUPomjh14EVqAXNcfa3CpIUZfBw26wKRz0AfEnTqrGBGGQF5Z9ibGNgY0vP0XriN65OWsy1qEUwzEkXq3rvvYyjMbJK7y1ROMdB9iRyObAW2qUq2xQwvhd7Mk6J/0Jesk8hESmmQdAmYsGKhae1xeozreszJ9UNcPgXfOgaQMH08t6cbtbj9O2ZJKSOfZ5zE8SQqarhviDJBcZG1syxkSt1BMwYv2KGQNaUmne5Byn2O6GVJGFr7Ab_hRDyE/.../

Scan moborobo(moborobo_en_official).exe - Powered by Reason Core Security