octres.dll

Microsoft Office Customization Tool Resources

Microsoft Corporation

OCTres provides the localized resources of the Korean language version (strings, images, icons, menu items) for the MS Office Customization tool. OCT is part of the Setup program and used to customize the installation of the Windows Installer-based Office.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Office Customization Tool Resources

Version:
15.0.4420.1017

MD5:
20ca2ba3dd7f050589602b83ce871b54

SHA-1:
fd2b446b0334b09071a8ad37e85d0331197798da

SHA-256:
5e960753f9f41ee014e150fe970dce7958d0546f2ec475bc0c0c1867f627c0f7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
1/14/2025 9:52:39 PM UTC  (today)

File size:
387.7 KB (396,968 bytes)

Product version:
15.0.4420.1017

Original file name:
octres.dll

File type:
Dynamic link library (Win64 DLL)

Language:
Korean (Korea)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\admin\ko-kr\octres.dll

Digital Signature
Authority:
Microsoft Corporation

Valid from:
7/26/2012 1:50:41 PM

Valid to:
10/26/2013 1:50:41 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
3300000088590E3C511FE26A67000100000088

File PE Metadata
Compilation timestamp:
9/29/2012 9:36:02 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
3072:vW2Gh8/0D7UGIPCDT3iek/o3Dt0em/WcuL7tw1TCy:u337nhP3iN/o69uo

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C0, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.7534

The file octres.dll has been seen being distributed by the following 2 URLs.

ftp://ftp.ptcl.net.pk/Helpdesk-Software/Office 2013/Office_Professional_Plus_2013_64Bit_English/admin/.../octres.dll