microsoft-office-windows-downloader.exe

The application microsoft-office-windows-downloader.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl1332a14.mvmfd.net and multiple other hosts. While running, it connects to the Internet address 161-108.furanet.com on port 80 using the HTTP protocol.
MD5:
62ad695da753f87e06094c4f8e7700a6

SHA-1:
661c163ed973d7a754499997f6f7e9e0959a3407

SHA-256:
89ea028266af303aec73d0c1002d5453308686916989ab8c5f4ddadd28c344c0

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
11/27/2024 1:11:08 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:Malavida-F [PUP]
2014.9-141118

AVG
Toolbar.Babylon
2015.0.3286

Baidu Antivirus
PUA.Win32.Malavida
4.0.3.141118

ESET NOD32
Win32/Malavida
8.10737

McAfee
Artemis!62AD695DA753
5600.6942

Trend Micro House Call
Suspicious_GEN.F47V1106
7.2.322

VIPRE Antivirus
Malavida
34876

File size:
142.4 KB (145,777 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\oud\microsoft-office-windows-downloader.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:OLk395hYXJBNW9vMjrHYZfLUwA7JKjy4FYOInW:OQq4FM/HYZowAgjtF2W

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file microsoft-office-windows-downloader.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 161-108.furanet.com  (91.192.108.161:80)

Remove microsoft-office-windows-downloader.exe - Powered by Reason Core Security