mp.exe

The executable mp.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from cdn.searchtooknow.com.
Version:
1.0.5822.27661

MD5:
d858314251bfbefdc070edd3315315cf

SHA-1:
9eee24c01cab1df8fbe3af2fd865ee8aca355f1c

SHA-256:
d9d555bb416cc478c46dd3a94791c727e35a2e270590edc873d3d8f0289a8c71

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
1/12/2025 1:00:25 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160215-2

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Trojan.Artemis!3835E114EF20
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.1710.0

Norman
Win32.Sality.3
29.02.2016 05:46:54

VIPRE Antivirus
Threat.4721115
47848

File size:
173.1 KB (177,240 bytes)

Product version:
2015.12.10

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\mp.exe

File PE Metadata
Compilation timestamp:
6/5/2014 7:58:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:gn3AcI4RBSvCj+ewRqqRU9UteEqq8V0ek+KFUEr8B3yPVsBJr9A2:QQKZXwxRU9UtUVYFUEregyV9A2

Entry address:
0x31E4

Entry point:
22, D8, 50, 2D, 68, 95, B6, 1F, 0D, E0, C0, 53, DF, 88, DE, B7, EC, 52, EB, 0A, BE, 82, 5A, F0, 74, F6, C2, 50, FF, CA, 8D, 05, 12, 18, B4, E8, 40, C6, C2, 06, E8, 4D, 00, 00, 00, 8A, FE, C6, C4, F1, 42, F6, C5, 27, 85, C5, FE, CC, 81, FB, 7E, CD, 00, 00, 71, 0D, 69, DF, FE, 09, D9, 9E, 8D, 15, 30, 35, D3, D3, 42, 85, CE, 89, C3, 8D, 38, 88, CB, 12, F5, 88, E4, 88, E4, 3B, C0, 2B, ED, FF, CE, 1C, 4B, 8D, 2F, 29, F6, 69, DF, A0, 1F, 1B, C0, C7, C0, 55, 7B, 24, BA, 03, CD, 89, CB, 46, 5A, 81, F9, CF, B9, 00...
 
[+]

Entropy:
7.8095  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file mp.exe has been seen being distributed by the following URL.

Remove mp.exe - Powered by Reason Core Security