fiksiki 2012 o dvdrip-avc by keeper torrent.exe

2007 Microsoft Office system

Era Tehno

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable fiksiki 2012 o dvdrip-avc by keeper torrent.exe, “Microsoft Script Editor” has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from flesh-rig-briefly.ru and multiple other hosts.
Publisher:
Microsoft Corporation  (signed by Era Tehno)

Product:
2007 Microsoft Office system

Description:
Microsoft Script Editor

Version:
12.0.6606.1000

MD5:
c9073738e64c5f6facc5d16844182e75

SHA-1:
42d7b0142ba45b2ba7682e2207d29cb9e4d1421e

SHA-256:
96e4e196bf96bed0c69e554cb263d67bdf3273293e81ffc632d3005c513f39e5

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/6/2024 6:26:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.14.16

File size:
839.5 KB (859,624 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
mse.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\fiksiki 2012 o dvdrip-avc by keeper torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/14/2016 2:00:00 AM

Valid to:
6/15/2017 1:59:59 AM

Subject:
CN=Era Tehno, O=Era Tehno, STREET="KIROVOGRADSKAJa Street, Building 42", L=Moscow, S=Moscow, PostalCode=117534, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
69A05FDE494793353A4495A3D4440917

File PE Metadata
Compilation timestamp:
7/12/2016 1:28:33 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1290

Entry point:
55, 8B, EC, B8, 38, 8B, 00, 00, E8, B3, FF, FF, FF, 53, 56, 57, C6, 45, F4, 3E, 8B, 85, 74, 77, FF, FF, 69, C0, F2, 41, 19, 10, 89, 85, 70, 77, FF, FF, 8B, 8D, 70, 77, FF, FF, 0F, AF, 8D, 74, 77, FF, FF, 89, 8D, 70, 77, FF, FF, 68, 84, 90, 44, 00, FF, 15, 9C, C0, 43, 00, 8B, 95, 74, 77, FF, FF, 03, 95, 74, 77, FF, FF, 89, 95, 70, 77, FF, FF, 6A, 00, FF, 15, B0, C0, 43, 00, 68, 90, 90, 44, 00, FF, 15, A0, C0, 43, 00, 68, 9C, 90, 44, 00, FF, 15, A0, C0, 43, 00, 68, A8, 90, 44, 00, 8B, 85, 74, 77, FF, FF, 50...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
235.5 KB (241,152 bytes)

The file fiksiki 2012 o dvdrip-avc by keeper torrent.exe has been seen being distributed by the following 2 URLs.

http://flesh-rig-briefly.ru/.../522378-masd

http://flesh-rig-briefly.ru/.../522378-masd