MyPhoneExplorer.exe

MyPhoneExplorer

Franz Josef Wechselberger

The application MyPhoneExplorer.exe by Franz Josef Wechselberger has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address www24.world4you.com on port 80 using the HTTP protocol.
Publisher:
F.J. Wechselberger  (signed by Franz Josef Wechselberger)

Product:
MyPhoneExplorer

Version:
1.08.0003

MD5:
7d3bdc1d1e1d21d7a34d95f3a64cb73d

SHA-1:
61ff6801b2b47a3848e27e716727ccb31014393a

SHA-256:
bedef759d70caec8c4f2c1cf2057a9b56c28f37906fb2b3a0995fb46462b1609

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:28:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.FranzJosefWechselberger.P
14.11.2.4

File size:
4.6 MB (4,849,368 bytes)

Product version:
1.08.0003

Original file name:
MyPhoneExplorer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\myphoneexplorer\myphoneexplorer.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
5/20/2011 2:00:00 AM

Valid to:
5/20/2014 1:59:59 AM

Subject:
CN=Franz Josef Wechselberger, O=Franz Josef Wechselberger, STREET=Dorf 140/2, L=Finkenberg, S=Tirol, PostalCode=6292, C=AT

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
10325DA705E4199D23C6971BB9EED78B

File PE Metadata
Compilation timestamp:
7/25/2012 1:32:19 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:8066ytOLuTW1lruLqRkir8yCbSYog+ECXLfrzJo/W:80ke4E1uLqRkirwbSO+EAJt

Entry address:
0x14AC

Entry point:
68, 20, 1D, 40, 00, E8, EE, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, A6, 46, 03, 7C, AF, 6C, E5, 45, A1, 8C, 7D, 23, 1F, 6D, 49, C3, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 79, 04, 00, 00, 00, 00, 4D, 79, 50, 68, 6F, 6E, 65, 45, 78, 70, 6C, 6F, 72, 65, 72, 00, 00, 00, 2B, 03, F0, 79, 47, 00, C0, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, AB, 00, 00, 00, FC, 58, AC, 7A, 89, 52, 3E, 46, 85, E5, 69, 60, A1, 27, 40, 2F, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
4.5 MB (4,730,880 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to www24.world4you.com  (81.19.145.44:80)

Remove MyPhoneExplorer.exe - Powered by Reason Core Security