octres.dll

Microsoft Office 自定义工具资源

Microsoft Corporation

OCTres provides the localized resources of the Chinese language version (strings, images, icons, menu items) for the MS Office Customization tool. OCT is part of the Setup program and used to customize the installation of the Windows Installer-based Office.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Office 自定义工具资源

Version:
15.0.4420.1017

MD5:
b439f5e8ce184cc0d94e3cbbdf6f9d97

SHA-1:
772d5ab25c233fec570767643423914ca45ebfa3

SHA-256:
7ac5ac4896711ce434d3c7fc40078209535eebd1d1ef1be1a06a86c88f0be480

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
1/14/2025 9:21:18 PM UTC  (today)

File size:
378.6 KB (387,696 bytes)

Product version:
15.0.4420.1017

Original file name:
octres.dll

File type:
Dynamic link library (Win64 DLL)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\admin\zh-cn\octres.dll

Digital Signature
Authority:
Microsoft Corporation

Valid from:
7/26/2012 1:50:41 PM

Valid to:
10/26/2013 1:50:41 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
3300000088590E3C511FE26A67000100000088

File PE Metadata
Compilation timestamp:
9/29/2012 9:36:02 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
3072:vB2Gh8/0D7UGIPCDT3iek/o3Dt0em/t5Tl8NUiCZ7:5337nhP3iN/o6zl8NUiC

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C0, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.7165

The file octres.dll has been seen being distributed by the following 2 URLs.

ftp://ftp.ptcl.net.pk/Helpdesk-Software/Office 2013/Office_Professional_Plus_2013_64Bit_English/admin/.../octres.dll