mxbh.exe

ZUNSHANG INFO TECH CO. LTD.

The application mxbh.exe by ZUNSHANG INFO TECH CO. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘mxbh’. While running, it connects to the Internet address IZ23O5WOAZBZ on port 80 using the HTTP protocol.
Publisher:
Monxeng Box  (signed by ZUNSHANG INFO TECH CO. LTD.)

Product:
Monxeng Box

Version:
2.0.0.3

MD5:
312b45791563c08bde185aa6588a0bca

SHA-1:
4e7a57a68f5857f295a4b8c43bb004a4c1dfe7c4

SHA-256:
492bf898e35169d1d626b51bc9b241f9d97fdf39002db3af3d864bd6458206d8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 11:31:49 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TopTools (M)
16.9.16.0

File size:
4.6 MB (4,856,472 bytes)

Product version:
2.0.0.3

Copyright:
Monxeng Box

Original file name:
Monxeng Box

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mxbh\mxbh.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/10/2016 3:08:55 PM

Valid to:
3/10/2017 3:08:55 PM

Subject:
CN=ZUNSHANG INFO TECH CO. LTD., O=ZUNSHANG INFO TECH CO. LTD., L=Changzhou, S=Jiangsu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
4F1846359241387E3EFE5A631480EEFE

File PE Metadata
Compilation timestamp:
9/13/2016 2:57:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:C0Jm7xcno5chInaRWoGmwvDn+cHW3BUfeGZ8qi1q8FAQFLOAkGkzdnEVomFHKnPi:hx8lnHDlWxUfeGyqi1q8FVFLOyomFHKK

Entry address:
0x164936

Entry point:
E8, 50, C5, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 50, 08, 67, 00, 75, 02, F3, C3, E9, F1, 0F, 00, 00, 51, C7, 01, 4C, 26, 61, 00, E8, D2, CB, 00, 00, 59, C3, 55, 8B, EC, 8D, 41, 09, 50, 8B, 45, 08, 83, C0, 09, 50, E8, 40, CA, 00, 00, F7, D8, 59, 1B, C0, 59, 40, 5D, C2, 04, 00, 55, 8B, EC, 8D, 41, 09, 50, 8B, 45, 08, 83, C0, 09, 50, E8, 22, CA, 00, 00, F7, D8, 59, 1B, C0, 59, F7, D8, 5D, C2, 04, 00, 55, 8B, EC, 56, 8B, F1, E8, AA, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, E8, B4, ED, FF, 59, 8B, C6, 5E, 5D...
 
[+]

Entropy:
6.6210

Code size:
1.9 MB (1,976,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
mxbh

Command:
C:\Program Files\mxbh\mxbh.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to IZ23O5WOAZBZ  (114.55.143.106:80)

Remove mxbh.exe - Powered by Reason Core Security