kak_sdelat_masku_ichigo_iz_bumagi.exe

Internet Explorer

Consortium Group ltd

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application kak_sdelat_masku_ichigo_iz_bumagi.exe, “Установщик надстроек Internet Explorer” by Consortium Group ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Consortium Group ltd)

Product:
Internet Explorer

Description:
Установщик надстроек Internet Explorer

Version:
11.00.9600.16428 (winblue_gdr.131013-1700)

MD5:
1258b5f643b71bdcef70e9af9567c1f8

SHA-1:
9f80004243f7050710078ef26ee7073892e65425

SHA-256:
2cde697437ba67be92655aa0d4e0638633df02a27aea08ae4d8eb3db905e2d6b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 8:34:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCube (M)
17.2.18.9

File size:
3.5 MB (3,623,528 bytes)

Product version:
11.00.9600.16428

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
ieinstal.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kak_sdelat_masku_ichigo_iz_bumagi.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/16/2015 3:00:00 AM

Valid to:
2/25/2016 2:59:59 AM

Subject:
CN=Consortium Group ltd, O=Consortium Group ltd, STREET="3RD FLOOR, C&h TOWERS,", STREET=CORNER OF GR.MARLBOROUGH UN GR.GEORGE STR., L=ROSEAU, S=ROSEAU, PostalCode=00152, C=DM

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D6D9F6CD54311DD57B715B621215CF32

File PE Metadata
Compilation timestamp:
1/9/2016 7:08:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2E7230

Entry point:
55, 8B, EC, 6A, FF, 68, 58, 61, 75, 00, 68, B0, 83, 6E, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, CC, 60, 75, 00, 33, D2, 8A, D4, 89, 15, 80, A2, 75, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 7C, A2, 75, 00, C1, E1, 08, 03, CA, 89, 0D, 78, A2, 75, 00, C1, E8, 10, A3, 74, A2, 75, 00, 33, F6, 56, E8, CA, 0F, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 95, 0C, 00, 00, FF, 15, B4, 60, 75, 00, A3, B4, A7, 75, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
3.3 MB (3,493,888 bytes)

Remove kak_sdelat_masku_ichigo_iz_bumagi.exe - Powered by Reason Core Security