node js x32.exe

2007 Microsoft Office system

PORT PROM

The executable node js x32.exe, “2007 Microsoft Office component” has been detected as malware by 1 anti-virus scanner.
Publisher:
M icrosoft Corporation  (signed by PORT PROM)

Product:
2007 Microsoft Office system

Description:
2007 Microsoft Office component

Version:
12.0.6606.1000

MD5:
aae94846d1fc9d4ae5f4dc8d396e50f8

SHA-1:
7656f815f6e17ada64be1c6f59010ec3ad1ce16a

SHA-256:
9b2d9db667ad3224e02d27de77b26276ac7cd2eca8068a60bc77609c6c4fe002

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/6/2024 7:58:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.6.18

File size:
805.5 KB (824,848 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
SetLang.Exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\node js x32.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/6/2016 6:00:00 PM

Valid to:
7/7/2017 5:59:59 PM

Subject:
CN=PORT PROM, O=PORT PROM, STREET="d. 33 str. 1, ul.1-Ya Brestskaya", L=Moscow, S=Moscow, PostalCode=125047, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ED626D75C5323A188C6E74611FD410E9

File PE Metadata
Compilation timestamp:
7/23/2016 1:47:06 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1010

Entry point:
55, 8B, EC, 81, EC, 94, 02, 00, 00, 53, 56, 57, C6, 85, 6F, FF, FF, FF, D6, 8D, 09, 68, 2D, 10, 40, 00, C3, CD, 7F, 8B, 85, CC, FE, FF, FF, C1, E8, D7, 89, 85, D4, FE, FF, FF, 8B, 95, CC, FE, FF, FF, 8B, 8D, D8, FE, FF, FF, D3, E2, 89, 95, D4, FE, FF, FF, 68, 84, 10, 49, 00, FF, 15, E4, C1, 48, 00, 8B, 85, D8, FE, FF, FF, 8B, 8D, D4, FE, FF, FF, D3, E8, 89, 85, D8, FE, FF, FF, 8B, 8D, DC, FE, FF, FF, C1, E9, 43, 89, 8D, D0, FE, FF, FF, 68, 88, 10, 49, 00, FF, 15, E8, C1, 48, 00, 8B, 95, D0, FE, FF, FF, 81...
 
[+]

Entropy:
6.8601

Developed / compiled with:
Microsoft Visual C++

Code size:
554.5 KB (567,808 bytes)

Remove node js x32.exe - Powered by Reason Core Security