1a115c4f-c5f7-b742-6f16-15bbd6e1b410_1d1f00619522ab4

Betriebssystem Microsoft Windows

Smart Distribyushn, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The file 1a115c4f-c5f7-b742-6f16-15bbd6e1b410_1d1f00619522ab4, “Ausführbare Datei für das Spiel FreeCell” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Smart Distribyushn, TOV)

Product:
Betriebssystem Microsoft® Windows®

Description:
Ausführbare Datei für das Spiel FreeCell

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
d90e26b40281d26ef5f8670a094d3ebb

SHA-1:
6e1042a0af499c34dc89cb0c7cabc048d8d75c77

SHA-256:
8db3a82696293b03ac516cf2ef44284bd52c4ac7575ba96cd90cf98ae608a54c

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 9:28:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.18.11

File size:
7.2 MB (7,570,984 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. Alle Rechte vorbehalten.

Original file name:
freecell.exe.mui

Language:
German (Germany)

Common path:
C:\ProgramData\microsoft\windows defender\scans\filesstash\1a115c4f-c5f7-b742-6f16-15bbd6e1b410_1d1f00619522ab4

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/21/2016 2:00:00 AM

Valid to:
5/12/2017 1:59:59 AM

Subject:
CN="Smart Distribyushn, TOV", OU=IT, O="Smart Distribyushn, TOV", STREET="vul. IVANA KUDRI, 37-A", L=Kiev, S=Kiev, PostalCode=01042, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
44F7AD0BD4F298AFA32D347ECF9E22C5

File PE Metadata
Compilation timestamp:
7/4/2015 1:36:44 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x7232E0

Entry point:
6A, 70, 68, 60, C8, B2, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 0C, D0, B2, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 58, D0, B2, 00, 59, 83, 0D, B0, CA, B2, 00, FF, 83, 0D, B4, CA...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
7.1 MB (7,485,440 bytes)