windowsphonerecoverytoolinstaller.exe

Windows Phone Recovery Tool 2.1.2

Microsoft Corporation

This is a self-extracting archive and installer. The file has been seen being downloaded from www.tamindir.com and multiple other hosts.
Publisher:
Microsoft  (signed by Microsoft Corporation)

Product:
Windows Phone Recovery Tool 2.1.2

Version:
2.1.2

MD5:
624c9cd7ded4cb3c37fa6bb282026a6a

SHA-1:
a42bede2b700643d58b5c70345b73f91d8e4e83f

SHA-256:
cb1decd44875c12b1aa3830353e7319b2cbd2c5af396fcd0975a50470a5d94ca

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
12/26/2024 2:43:09 PM UTC  (today)

File size:
2.2 MB (2,297,184 bytes)

Product version:
2.1.2

Copyright:
Copyright (c) Microsoft. All rights reserved.

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Microsoft Corporation

Valid from:
6/4/2015 6:42:45 PM

Valid to:
9/4/2016 6:42:45 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
330000010A2C79AED7797BA6AC00010000010A

File PE Metadata
Compilation timestamp:
12/8/2014 10:44:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:Bi+nwxGDdPYl+Ij5XmZHb0HNUMpJvXl1AdtyZnSw+7OTwbR9XWIQZBFdt2/HsTgP:XnwLl+IQdNMF0yRy9XEFbvwi6anqt

Entry address:
0x2945F

Entry point:
E8, 00, 3A, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 00, 20, 46, 00, 75, 02, F3, C3, E9, 89, 41, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 5C, 3F, 46, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 60, 20, 46, 00, 01, 0F, 82, 3A, 42, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8...
 
[+]

Entropy:
7.4229

Code size:
270.5 KB (276,992 bytes)

The file windowsphonerecoverytoolinstaller.exe has been seen being distributed by the following 28 URLs.

http://www.tamindir.com/indir/MjAxNi0wNS0xNiAxNzowNzo0MQ==/windows-device-recovery-tool/windows/.../

https://docs.google.com/uc?authuser=0&id=0B5-f40WmpEd5OHp2TFRfX0xueFE&export=download

q=http://bit.ly/WPRCWP8&redir_token=RaPg_xE4nDJVPHd-7S32VRwXqGB8MTQ0MTgzNjc5MkAxNDQxNzUwMzky

http://srwtck.com/get?key=b11e8793cade0a4fedc9f17323b20200&ref=http://windowsphoneapps.es/2015/02/windows-phone-recovery-tool-la-herramienta-de-microsoft-para-regresar-windows-phone-8-1-desde-windows-10/&uid=87688765&out=http://download-fds.webapps.microsoft.com/supportFiles/phones/files/.../WindowsPhoneRecoveryToolInstaller.exe

http://dc335.4shared.com/download/.../windowsphonerecoverytoolinstal.exe

http://download.informer.com/.../windowsphonerecoverytoolinstaller.exe

http://download.informer.com/.../windowsphonerecoverytoolinstaller.exe

http://download.findmysoft.com/2015/09/.../Windows-Phone-Recovery-Tool_2.1.2.exe

https://cloclo26.cldmail.ru/2qNfKk32Q73caA8zc8Z1/G/.../NZGiL4gyL?key=cc2f11615d0e65956ae6d3062daec003d3729891

temp:WindowsPhoneRecoveryToolInstaller (1).exe

q=http://go.microsoft.com/.../?LinkID=525569&redir_token=6oZi56xyJYkKYuB1uOBmDY2uJQF8MTQ0MzUzNjg5NEAxNDQzNDUwNDk0

temp:WindowsPhoneRecoveryToolInstaller.exe