konspekt-uroku-na-temu-chim-mozhe-pishatis-ukranetc.-pershiy-urok-2015-2016-n.r.--rozumaka.exe

Операционная система Microsoft Windows

Feniks Tekhniks, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable konspekt-uroku-na-temu-chim-mozhe-pishatis-ukranetc.-pershiy-urok-2015-2016-n.r.--rozumaka.exe, “Исполняемый файл для игры "Mahjong Titans"” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Feniks Tekhniks, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Mahjong Titans"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
06adc1c900348e6f41ac64591601c064

SHA-1:
62f097a58986e919ddc604fcea29f2101b137d83

SHA-256:
8041d0601b230e77484ff93c1942a715e358c2da655ee2524fcde5e95b393614

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
8/6/2025 9:10:33 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.10.19

File size:
2.7 MB (2,821,400 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
mahjong.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\10 01 20017\konspekt-uroku-na-temu-chim-mozhe-pishatis-ukranetc.-pershiy-urok-2015-2016-n.r.--rozumaka.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/17/2016 3:00:00 AM

Valid to:
7/23/2017 2:59:59 AM

Subject:
CN="Feniks Tekhniks, TOV", OU=IT, O="Feniks Tekhniks, TOV", STREET="vul. Paustovskoho, 37", L=Kryzhanivka, S=Odeska, PostalCode=67562, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5C81C3A71C4D60F7AF7FBCE11853B06A

File PE Metadata
Compilation timestamp:
6/21/2014 7:06:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x5F980

Entry point:
6A, 70, 68, 80, 20, 46, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 0C, 20, 46, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 30, 20, 46, 00, 59, 83, 0D, 38, F0, 6B, 00, FF, 83, 0D, 3C, F0...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
387 KB (396,288 bytes)