mpas-fe.exe

Microsoft Malware Protection

Microsoft Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from definitionupdates.microsoft.com.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Malware Protection

Description:
AntiMalware Definition Update

Version:
1.219.771.0

MD5:
501250934c4ed97ad5bcfa112bd8ba24

SHA-1:
c2a4dbfb70b23d8841003e628ae90332c6d4cc39

SHA-256:
ca71a399b418b0445c2856f63ec46a27a11ce6c1d2ea0e9ae6774ffb44a0008f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/25/2024 1:16:58 AM UTC  (today)

File size:
39.8 MB (41,688,344 bytes)

Product version:
1.219.771.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
mpas-fe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\wsusoffline106\wsusoffline\client\wddefs\x86-glb\mpas-fe.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
6/4/2015 1:42:45 PM

Valid to:
9/4/2016 1:42:45 PM

Subject:
CN=Microsoft Corporation, OU=AOC, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
3300000109E3CDCA941016A298000100000109

File PE Metadata
Compilation timestamp:
5/4/2016 3:11:08 AM

OS version:
10.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
786432:+AQ0wFtxnVA5A0o/lX9aLBbVkR/YKrB7SiGz6SEwCslup:+A8nVuARtNadbVkp5JSKp

Entry address:
0x7340

Entry point:
E8, 87, 00, 00, 00, E9, 88, FE, FF, FF, 3B, 0D, 14, 00, 41, 00, 75, 02, F3, C3, E9, 9C, 05, 00, 00, 32, C0, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 75, 07, C6, 05, 70, 07, 41, 00, 01, E8, 7F, 06, 00, 00, E8, DC, 73, 00, 00, 84, C0, 75, 04, 32, C0, 5D, C3, E8, ED, 1C, 00, 00, 84, C0, 75, 0A, 6A, 00, E8, ED, 73, 00, 00, 59, EB, E9, B0, 01, 5D, C3, 8B, FF, 55, 8B, EC, 80, 3D, 70, 07, 41, 00, 00, 74, 06, 80, 7D, 0C, 00, 75, 12, FF, 75, 08, E8, D1, 1C, 00, 00, FF, 75, 08, E8, C2, 73, 00, 00, 59, 59, B0, 01, 5D...
 
[+]

Entropy:
7.9983  (probably packed)

Code size:
59.5 KB (60,928 bytes)

The file mpas-fe.exe has been seen being distributed by the following URL.