Microsoft Toolkit.exe

Microsoft Toolkit

This is a setup program which is used to install the application. The file has been seen being downloaded from www.datafilehost.com and multiple other hosts.
Product:
Microsoft Toolkit

Version:
2.4.3.0

MD5:
1c5a2b27ce7e1a57e34dc5bf2311027f

SHA-1:
61645de7674c6660b4817b26caa3bb811f8a4541

SHA-256:
a0cf676291c17c0c316414df7369dbd8ce3f0f5825f843c496bffaf141bd34da

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2017 8:37:54 AM UTC  (today)

File size:
36.1 MB (37,803,008 bytes)

Product version:
2.4.3.0

Copyright:
CODYQX4

Original file name:
Microsoft Toolkit.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\vmwarednd\840addbe\microsoft toolkit.exe

File PE Metadata
Compilation timestamp:
3/30/2013 7:15:22 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
786432:OYEGPqe8GGFhGbej+RLIWtIrKOBCpwkbdQ+kj45icy:OpGyZrWU0tLNdQ34

Entry address:
0x23B39DA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 04, 00, 03, 00, 00, 00, 30, 00, 00, 80, 0E, 00, 00, 00, 78, A6, 05, 80, 10, 00, 00, 00, 0E, A7, 05, 80, 18, 00, 00, 00, 26, AA, 05, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 06, 00, 02, 00, 00, 00, 70, 00, 00, 80, 03, 00, 00, 00, FC, 04, 00, 80, 04, 00, 00, 00, C8, 15, 00, 80, 05, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
35.7 MB (37,427,712 bytes)

The file Microsoft Toolkit.exe has been seen being distributed by the following 50 URLs.

http://www.datafilehost.com/get.php?file=0cebb95f

http://download856.mediafire.com/j2m4m47aqfng/.../Microsoft Toolkit.exe

https://doc-0s-a8-docs.googleusercontent.com/docs/securesc/19ubg0c2j8gm4tvljhm9634g5qurd76m/b0u8dvfpnn5iah9b0mi06gd1it0psr58/1477303200000/.../17003687818447243542/0B2GIwMMRxHOxNS1kcXgtcFRKcHM?e=download

http://192.168.0.40:5100/.../office????Microsoft Toolkit 2.4.3.exe

http://mafreebox.freebox.fr/api/v3/.../L0Rpc3F1ZSBkdXIvVmlkw6lvcy9GSUxNIFVTL1t3d3cuQ3Bhc2JpZW4ucGVdIE1pY3Jvc29mdCBPZmZpY2UgUHJvZmVzc2lvbmFsIFBsdXMgMjAxMyBWTCBFZGl0aW9uIHg4NiB4NjQgRlIvTWljcm9zb2Z0VG9vbGtpdC5leGU=?inline=0

https://dl.dropboxusercontent.com/s/.../Microsoft Toolkit 2.4.3 - RePack.exe

https://www.dropbox.com/sh/3z08b1yrla24rwy/.../Microsoft.Toolkit.2.4.3.Stable.exe

https://doc-04-2k-docs.googleusercontent.com/docs/securesc/66fjgi2h84pj72qhd77k9jliireujbc2/2i62ccoln5vv4293s6jja8ess359br4p/1433872800000/.../09098515893115134790/0BxnMiCMkJfMObFdRdnNEQ0t4Ymc?e=download

http://online.b1.org/rest/online/download/.../Microsoft Toolkit.exe

https://seed6-2.debrid-link.fr/dl/142327/14357d3f7f1723aa178/.../MicrosoftToolkit.exe

https://onedrive.live.com/.../oZEV0IrZnEsttEs=1

http://www.ingenieriabiobio.cl/nube/index.php/s/.../download

https://docs.google.com/uc?export=download&confirm=QwB6&id=0B9qWMFjE2hYiOGhLU0tJNWRPSGs

http://shelllumber.com/.../Microsoft Toolkit.exe

https://mega.nz/persistent/.../qgcmxCzL

https://doc-14-3g-docs.googleusercontent.com/docs/securesc/0459ci0b5fflqfpke4kli9393d8oa1du/k36kj2fboksvimdap8tf1bp6jk31pucv/1466064000000/05551278763110502265/.../0BzFhZkzhr1SULUl3N0g2Sm01eUU?e=download

https://mega.co.nz/persistent/.../dNtzyIaZ

http://download1025.mediafire.com/e4d07bms6ekg/.../Microsoft Toolkit.exe

https://doc-10-58-docs.googleusercontent.com/docs/securesc/dmj62v25vq0kjfs8na7s1t114pn72h43/efmrsvl67l8nrj7nh95i0d2h201v4p5o/1473098400000/08188774905703127424/.../0B-MJJuBNkN3EOVJPVHJrS1pwWkE?e=download

https://mega.nz/temporary/.../gcVUmCgJ

https://doc-14-9g-docs.googleusercontent.com/docs/securesc/t5a5dp4kg7r6p04tcdggekpfktcdibg8/cvlecd7e4809g3hd67iiiiaekjimbtha/1458734400000/.../04948001743321074377/0B6WjgdnUNAxid1drUFo2dVBrZHc?e=download

temp:Microsoft Toolkit.exe

Latest 30 of 61 download URLs

Scan Microsoft Toolkit.exe - Powered by Reason Core Security