dumpper-v.70.4-jumpstart.exe

Операционная система Microsoft Windows

Smart Isteit, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable dumpper-v.70.4-jumpstart.exe, “Исполняемый файл для игры "Mahjong Titans"” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Smart Isteit, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Mahjong Titans"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
6992ffd2c8391f1ea82ce4acc2d30fb5

SHA-1:
60d4c1c1f8b86ebaf618056ecfe14dc7efe87490

SHA-256:
a0337fb5d79f181b6a618f7a805980fff76f453c3dc5dcc2d6268fcbbc6c2924

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 12:31:29 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.2.6

File size:
5.9 MB (6,219,264 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
mahjong.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dumpper-v.70.4-jumpstart.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/21/2016 3:00:00 AM

Valid to:
5/11/2017 2:59:59 AM

Subject:
CN="Smart Isteit, TOV", OU=IT, O="Smart Isteit, TOV", STREET="Vulytsya Startova, Budynok 3", L=Misto Dnipropetrovsk, S=Dnipropetrovska, PostalCode=49041, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B4959D3231A5090CC5107015AF7B970F

File PE Metadata
Compilation timestamp:
3/28/2015 12:26:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x5D8DC8

Entry point:
6A, 70, 68, 60, 28, 9E, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 18, 30, 9E, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 34, 30, 9E, 00, 59, 83, 0D, 38, 2A, 9E, 00, FF, 83, 0D, 3C, 2A...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
5.8 MB (6,133,760 bytes)

Remove dumpper-v.70.4-jumpstart.exe - Powered by Reason Core Security