octres.dll

Recursos da Ferramenta de Personalização do Microsoft Office

Microsoft Corporation

OCTres provides the localized resources of the Portuguese language version (strings, images, icons, menu items) for the MS Office Customization tool. OCT is part of the Setup program and used to customize the installation of the Windows Installer-based Office.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Recursos da Ferramenta de Personalização do Microsoft Office

Version:
15.0.4420.1017

MD5:
3a34e2fe69de173e648b19a107a9afb3

SHA-1:
602a2ea0c550fd56786411d994513f682804de41

SHA-256:
e6db08543987a3c1b6da47b9e6259fab2432fb7aefa860b45c4bff598916761e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
1/14/2025 9:53:13 PM UTC  (today)

File size:
421.7 KB (431,816 bytes)

Product version:
15.0.4420.1017

Original file name:
octres.dll

File type:
Dynamic link library (Win64 DLL)

Language:
Portuguese (Brazil)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\admin\pt-br\octres.dll

Digital Signature
Authority:
Microsoft Corporation

Valid from:
7/26/2012 1:50:41 PM

Valid to:
10/26/2013 1:50:41 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
3300000088590E3C511FE26A67000100000088

File PE Metadata
Compilation timestamp:
9/29/2012 9:36:02 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
3072:v1J2Gh8/0D7UGIPCDT3iek/o3Dt0em/ilzz0XLsyY9AFmZ7sLu7:tJ337nhP3iN/o66d

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C0, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.6155

The file octres.dll has been seen being distributed by the following 2 URLs.

ftp://ftp.ptcl.net.pk/Helpdesk-Software/Office 2013/Office_Professional_Plus_2013_64Bit_English/admin/.../octres.dll