malwarescanimporter.vshost.exe

Microsoft Visual Studio 2010

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft (R) Visual Studio (R) 2010

Description:
vshost32.exe

Version:
10.0.30319.1

MD5:
02be6d33b1edbc61c79882d3f556bd8a

SHA-1:
8d0afa78893ae5f04e505db0d76d0d50cf34e7da

SHA-256:
4c9f9b9de2ffeea9ccc6524d05ea5b78a14c1642cecc189fe40e7a57a6c294b3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/26/2024 1:49:30 PM UTC  (today)

File size:
11.3 KB (11,600 bytes)

Product version:
10.0.30319.1

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
vshost32.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
Microsoft Corporation

Valid from:
12/7/2009 5:40:29 PM

Valid to:
3/7/2011 5:40:29 PM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6101CF3E00000000000F

File PE Metadata
Compilation timestamp:
3/18/2010 7:02:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:LzoWn3xB1BfWKnWZQKPnEtObMacxc8hjeyveCf0pnvC:ZhNfWKnWZLXci2jpv8vC

Entry address:
0x2AEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2021

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
3 KB (3,072 bytes)

The file malwarescanimporter.vshost.exe has been seen being distributed by the following 12 URLs.

ftp://kyi.ddns.net/IT_Share/.../NewStoreProject.vshost.exe

ftp://81.136.234.109/.../HoSync.vshost.exe

http://f2h.nana10.co.il/.../yt1fnpb5tkgy|c26c8078c13244e3073fd7e9a2aa6261|.exe

temp:PokeGen.vshost.exe

http://fileice.net/offercheck.php?file=240009&t=1471454483

https://drive.google.com/uc?id=0B0P6ZpsakdeTT2UwQm5BNm5JdWM&export=download