vasiliy mahanenko mir barlionyi audiokniga.exe

2007 Microsoft Office system

Inergen

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable vasiliy mahanenko mir barlionyi audiokniga.exe, “2007 Microsoft Office component” has been detected as malware by 1 anti-virus scanner. This is a setup program which is used to install the application. The file has been seen being downloaded from oksrv.ru.
Publisher:
Microsoft Corporation  (signed by Inergen)

Product:
2007 Microsoft Office system

Description:
2007 Microsoft Office component

Version:
12.0.6606.1000

MD5:
b0aeab0635c8ea51bc9405439f52f0f4

SHA-1:
13407e82327220364070a7b79cfdae23840fc38b

SHA-256:
2cccf8d215fb3b6afef2a73e3eeec47cfdfd0748c0c96c5e3e99168a859f4872

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/28/2024 3:59:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.19.17

File size:
593.5 KB (607,744 bytes)

Product version:
12.0.6606.1000

Copyright:
© 2006 Microsoft Corporation. All rights reserved.

Original file name:
SetLang.Exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vasiliy mahanenko mir barlionyi audiokniga.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/25/2016 3:00:00 AM

Valid to:
5/26/2017 2:59:59 AM

Subject:
CN=Inergen, O=Inergen, STREET="AVENUE VOLGOGRAD, House 93, Building 2, ROOM II ROOM 12,", L=Moscow, S=Moscow, PostalCode=109117, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C9BE03B759B3C958ED3BBFB001506309

File PE Metadata
Compilation timestamp:
6/18/2016 6:18:07 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:7PzEupMvSVQ45CrGhKcWBQM+T+jYc45dNju8SZn243e20e7BnBXrDCAc8Dya1+Wt:0VKSyhdAQMGIqdpzQn2ElNl7cXqfrXj9

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, B0, 03, 00, 00, C6, 85, 44, FF, FF, FF, EA, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15, 1C, 19, 49, 00, 89, 2D, FC, 18, 49, 00, C6, 85, 05, FE, FF, FF, ED, A1, 2C, C0, 48, 00, A3, 44, 19, 49, 00, 8B, 0D, 44, 19, 49, 00, 89, 8D, 40, FE, FF, FF, C7, 85, 3C, FE, FF, FF, 00, 00, 00, 00, 68, 48, 19, 49, 00, 8B, 15, 48, 10, 49, 00, 52, 68, 00, 00, 00, 80, FF, 95, 40, FE, FF, FF, 89, 85, 44, FE, FF, FF, 83, BD, 44, FE, FF, FF, 00, 74, 02, CD, 05, C6, 85, 10, FD, FF, FF, 48, E8, 82, 03, 00, 00, A3, 24...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
554.5 KB (567,808 bytes)

The file vasiliy mahanenko mir barlionyi audiokniga.exe has been seen being distributed by the following URL.