patch1172529-1379to1184516-1380-64bit.exe

Microsoft Office Outlook

Era Tehno

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable patch1172529-1379to1184516-1380-64bit.exe, “Microsoft Office Outlook OST Integrity Check” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Era Tehno)

Product:
Microsoft Office Outlook

Description:
Microsoft Office Outlook OST Integrity Check

Version:
12.0.6606.1000

MD5:
f4e673aaf9ec4ebafee6b6e1681d49b0

SHA-1:
a13216c510caa663be0598fa17ca3ced5fa48fc7

SHA-256:
4be808fea6ca3f34e8a41d1b279ddd195308de5c3f496ced0a7b69b830232edb

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/6/2024 6:39:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.15.9

File size:
892 KB (913,384 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
ScanOST.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\patch1172529-1379to1184516-1380-64bit.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/14/2016 7:00:00 AM

Valid to:
6/15/2017 6:59:59 AM

Subject:
CN=Era Tehno, O=Era Tehno, STREET="KIROVOGRADSKAJa Street, Building 42", L=Moscow, S=Moscow, PostalCode=117534, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
69A05FDE494793353A4495A3D4440917

File PE Metadata
Compilation timestamp:
7/12/2016 9:46:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1030

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 8B, 45, EC, 2B, 45, F0, 89, 45, F8, 8B, 4D, F4, 0F, AF, 4D, F0, 89, 4D, F0, FF, 15, 70, 44, 4B, 00, 8B, 55, F8, 2B, 55, F0, 89, 55, F4, 8B, 45, F0, 50, FF, 15, 44, 45, 4B, 00, FF, 15, 70, 44, 4B, 00, 68, 4C, 10, 4D, 00, FF, 15, 74, 44, 4B, 00, 68, 64, 10, 4D, 00, FF, 15, 78, 44, 4B, 00, 8B, 4D, EC, 69, C9, 56, A0, EC, 11, 89, 4D, F8, 68, 6C, 10, 4D, 00, FF, 15, 7C, 44, 4B, 00, 8B, 55, F8, 8B, 4D, EC, D3, E2, 89, 55, F8, 68, 74, 14, 00, 00, A1, 34, CB, 4D, 00, 50, FF, 15...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
715.5 KB (732,672 bytes)

Remove patch1172529-1379to1184516-1380-64bit.exe - Powered by Reason Core Security