VC_redist.x86.exe

Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918

Microsoft Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from mega.nz and multiple other hosts.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918

Version:
14.0.23918.0

MD5:
476cc253800d5ee8577f541e17a90476

SHA-1:
7a672ae60fb7e029597c6a183cb7936eaff31a98

SHA-256:
15dc9852a32ea35fc2a3ef99535802dc2d99bd122b3926686e4c75d042c52b7b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
11/23/2024 9:38:39 AM UTC  (today)

File size:
13.3 MB (13,969,576 bytes)

Product version:
14.0.23918.0

Copyright:
Copyright (c) Microsoft Corporation. All rights reserved.

Original file name:
VC_redist.x86.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\package cache\5fadbc63-c663-33ee-8b4c-746152b316ed\packages\vcredistd14\vc_redist.x86.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
6/4/2015 12:42:45 PM

Valid to:
9/4/2016 12:42:45 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
330000010A2C79AED7797BA6AC00010000010A

File PE Metadata
Compilation timestamp:
2/13/2015 1:42:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
393216:dmlp+dkBSuF2SfUfn6lLBk2yFb/NRi2T9ZetcMH:4p+Ty2SfUfnX2yh/NRi6ctcC

Entry address:
0x28494

Entry point:
E8, 06, 1F, 00, 00, E9, 89, FE, FF, FF, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 88, 8F, 45, 00, 00, 74, 05, E9, 6E, 1F, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F...
 
[+]

Entropy:
7.9963  (probably packed)

Code size:
229 KB (234,496 bytes)

The file VC_redist.x86.exe has been seen being distributed by the following 14 URLs.

https://mega.nz/temporary/.../hdBi3QiY

http://slade.mancubus.net/files/vcredist/.../vc_redist.x86.exe

http://dl3.vessoft.com/files2/m/microsoftvc_windows/14.0.24215.1/.../vc_redist.x86.exe

http://adf.ly/N=jUJGoedlH5RiwNO4ig8nvLZ0GN9X3abkmVxmvcYfWNQmudbvWclzjMc1mQ9DzNbl2FZT0NLimJNzvNbkS19ykYb13UdTuYbtGY9zhNZlCR8T5LL32YIWvOM0y08C5MYyjkNjkM

http://222.165.175.166/data/f76330402cd04a37/download.microsoft.com/download/9/b/3/.../vc_redist.x86.exe

https://download.microsoft.com/download/e/6/6/.../vc_redist.x86.exe

http://srwtck.com/get?key=b11e8793cade0a4fedc9f17323b20200&ref=https://www.youtube.com/watch?v=18-NocobSQk&uid=87647413&out=http://download.microsoft.com/download/9/b/3/.../vc_redist.x86.exe

http://adf.ly/Y=jUBGoedlH5RiwNO4ig8nvLZ0GN9X3abkmVxmvcYfWNQmudbvWclzjMc1mQ9DzNbl2FZT0NLimJNzvNbkS19ykYb13UdTuYbtGY9zhNZlCR8T5LL32YIWvOM0y08C5MYyjkNjkM

http://adf.ly/M=DUJGoedlH5RiwNO4ig8nvLZ0GN9X3abkmVxmvcYfWNQmudbvWclzjMc1mQ9DzNbl2FZT0NLimJNzvNbkS19ykYb13UdTuYbtGY9zhNZlCR8T5LL32YIWvOM0y08C5MYyjkNjkM

https://download.microsoft.com/download/9/3/F/.../vc_redist.x86.exe