microsoft_word.exe

Sod

LAM Proactive And Investments Ltd

The application microsoft_word.exe, “Sod Setup ” by LAM Proactive And Investments has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.contentcurrentchuckle.com.
Publisher:
LAM Proactive And Investments Ltd  (signed and verified)

Product:
Sod

Description:
Sod Setup

Version:
2.0.4.2

MD5:
3bc9015c932c03dc303b3300542036c1

SHA-1:
44e63802df305a51e11037d264d21e0341063105

SHA-256:
d3b8b3554f4dd2ac1038046c05b3bd8a736603320e07d21e7459ccc74b60e71e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 2:22:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.12.16

File size:
1.3 MB (1,398,616 bytes)

Product version:
1.5

Copyright:
Program

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\microsoft_word.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/17/2016 7:17:01 AM

Valid to:
8/18/2017 7:17:01 AM

Subject:
CN=LAM Proactive And Investments Ltd, O=LAM Proactive And Investments Ltd, L=Herzliya, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
73CF7C9535C901AED579B1BA

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9792

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file microsoft_word.exe has been seen being distributed by the following URL.

http://www.contentcurrentchuckle.com/vXt37gkoWuaBBRJvUTv0IZ_dcCoFATpxXHGbq9JSBDLHIor zjJ8ZpBNLy6nTVQHv4gX4stQpX8s8ifBCoS65EzPIK3aahfn_Nrfn9sMUqXHmwCxretmk rv9S sZ9rD2Z5t47W4rCI0pRNHsALiWz8EoVG2fhu7gSnMArfjmTCjJPP3sWgzaW2Y0kDk6uaw_4NYeaUk5yRXF6lm4Nd1pvrFaep2JdGo8CQ1QA0O2EU6JwJcHVGefTD TrXI5CTmgku2tVbghnwW0WyT2iq97S60IlI8kGucZR2xXm15IsQZfi wqLugn3Nn1wG8t_Plw5MI7SYd5NOe3E5oBaumRCpLcCnz_MB0BnJQWzpG62Wf3S9PH4C6xt0SqDpht0zA9cHt6AvGPkrBvLU8rRYsray7NIgmLDVxYgeyR3eRvtb0yJCAHPcN Rx1Ys66fKPPn8DvH2VPnl5ppGBbsdgss4Ds4J5tdUCgfy_rwwEse c826job77MufXD1zsu2uei3dk11SNc-G3oAAES3 X2edlyj6xwREh4aWEJNDti79dICek84jjHQjYWHquAQju3BvMY4K1xUDBCMWuro9UY K6r6j9k_ G7XNngtEYECdwDadKo9T1 4AyQ=

Remove microsoft_word.exe - Powered by Reason Core Security