mp.exe

The application mp.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from cdn.splendorsearch.com.
Version:
1.0.5872.5213

MD5:
9fe592e848b31797c9c4998af190fdf4

SHA-1:
5713f8209adcb8c532feac14be7d59b60c5f4ba1

SHA-256:
af09a1a4f61b69a6b23a009e8dfe8c87d92d464806337ee4ad9ffd2a9e83f6dd

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 11:48:06 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160216-0

AVG
Win32/Sality
2015.0.4530

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Program.Artemis!7A0367C52AA8
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.6352.0

VIPRE Antivirus
Threat.4721115
47240

File size:
169.1 KB (173,200 bytes)

Product version:
2016.01.29

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mp.exe

File PE Metadata
Compilation timestamp:
6/5/2014 5:28:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:in3AcI4RBSeCCgHovRxSGBnJyIxi20NfdDut2AEBx1vnGXJMTy9HLw/ZNPCC:CQSECIGdgjdN1DAw77y9aCC

Entry address:
0x31E4

Entry point:
8D, 05, BD, B9, 4B, 1B, 0F, AF, E8, 0F, AF, D5, 0F, B6, DF, 8D, 0D, D7, CA, D7, 80, 89, D6, 28, CF, 69, C0, 61, D8, C4, CF, F3, 0F, BE, CA, 3B, EB, 3A, C4, 52, 29, ED, 12, D7, 69, FD, 10, 80, 3C, CA, 86, C4, F3, 68, 02, 8F, F5, 00, 51, C6, C1, C7, 86, CE, E8, 00, 00, 00, 00, 8A, F2, 81, F0, 5B, 2F, 16, AE, 42, 43, 6B, F6, 00, 1C, 08, F7, C3, EE, 21, D6, C2, F2, 0B, F6, F6, C7, 15, 0C, EC, 5A, B8, E6, C3, 79, BE, 03, F1, 8A, DB, 81, CF, 5E, B8, B1, 74, 0F, B6, F9, 69, F0, 9B, F2, 54, E4, 3D, 46, 65, 61, 1A...
 
[+]

Entropy:
7.8526  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file mp.exe has been seen being distributed by the following URL.

Remove mp.exe - Powered by Reason Core Security