MrPs.exe

MrPs

The executable MrPs.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘3f9ff86ff0a8176dab28f288cc422f3a’. The file has been seen being downloaded from 61055875-866111160821565096.preview.editmysite.com.
Product:
MrPs

Version:
1.0.0.0

MD5:
2121f347987a92bd65425dcffa673ebd

SHA-1:
8642d35b97b831b2a61df33e1b7ad10c72293ccb

SHA-256:
7d9bef461888c54fc62d565ec0e3ea3b1782fd0b7ac3b2a231566bd8f98d24a8

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 9:29:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Trojan.Rootkit (H)
16.2.7.21

File size:
112 KB (114,688 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2016

Original file name:
MrPs.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\mrps.exe

File PE Metadata
Compilation timestamp:
2/8/2016 2:05:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:tpDi5qOft/v+RxZuFdb0GUmd1s5FpcLM7zt1flF3dJWBFsoGYbtPEjGgIFQQ:txi5TUK0JusLHHt13NKsoGK1oGgIFQQ

Entry address:
0x1A52E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.5846

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
97.5 KB (99,840 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
3f9ff86ff0a8176dab28f288cc422f3a

Command:
"C:\users\{user}\appdata\local\temp\svchost.exe"..


The file MrPs.exe has been seen being distributed by the following URL.

Remove MrPs.exe - Powered by Reason Core Security