modmanager1 1 23.exe

2007 Microsoft Office system

Galantis MSK

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable modmanager1 1 23.exe, “2007 Microsoft Office component” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Galantis MSK)

Product:
2007 Microsoft Office system

Description:
2007 Microsoft Office component

Version:
12.0.6606.1000

MD5:
2447cde4890187d40fe7c3a43c5a8862

SHA-1:
74693f1e5bedb8976cf59228fd9db4fc924cc523

SHA-256:
9801e012e82e59ff9a869f684432899435dcac51b6679c54b03176c842a107e1

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 3:56:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.30.8

File size:
794 KB (813,040 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
SetLang.Exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\modmanager1 1 23.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/27/2016 3:00:00 AM

Valid to:
6/28/2017 2:59:59 AM

Subject:
CN=Galantis MSK, O=Galantis MSK, STREET="d. 163 korp. 1, prospekt Mira", L=Moscow, S=Moscow, PostalCode=129226, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
25391A5A8B498410563100ED497340FE

File PE Metadata
Compilation timestamp:
7/20/2016 3:57:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x2070

Entry point:
55, 8B, EC, 81, EC, 64, 02, 00, 00, 53, 56, 57, C6, 85, 6F, FF, FF, FF, D6, 8D, 09, 68, 8D, 20, 40, 00, C3, CD, 7F, C7, 85, C0, FE, FF, FF, 29, 00, 00, 00, 81, BD, C0, FE, FF, FF, 06, A1, 00, 00, 76, 02, EB, 23, 8B, 85, C0, FE, FF, FF, 83, C0, 15, 89, 85, C0, FE, FF, FF, 68, 70, E1, 48, 00, FF, 15, 84, 90, 48, 00, B9, C3, 01, 00, 00, 85, C9, 75, CF, 8B, 95, B4, FE, FF, FF, 8B, 8D, D4, FE, FF, FF, D3, E2, 89, 95, D4, FE, FF, FF, A1, B4, 39, 4C, 00, 50, FF, 15, 4C, 92, 48, 00, 8B, 8D, D4, FE, FF, FF, 2B, 8D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
542.5 KB (555,520 bytes)

Remove modmanager1 1 23.exe - Powered by Reason Core Security