msetup_x86.exe

Microsoft Windows NT Operating System

Microsoft Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from microsoft-mathematics.en.softonic.com.
Publisher:
Microsoft Corporation

Product:
Microsoft(R) Windows NT(R) Operating System

Description:
Win32 Cabinet Self-Extractor

Version:
4.71.1015.0

MD5:
42057e8925624af2e474c4a0f131c8c9

SHA-1:
4334075959a6bfe082e6df5ae0ab2f08704e4689

SHA-256:
323a97679c12ff3941da757e856dd5125afb7cc0ebbb1ff296244a1b895b393d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:32:32 PM UTC  (today)

File size:
17.7 MB (18,519,640 bytes)

Product version:
4.71.1015.0

Copyright:
Copyright (C) Microsoft Corp. 1995

Original file name:
WEXTRACT.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\msetup_x86.exe

File PE Metadata
Compilation timestamp:
7/15/1997 5:18:12 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:A5kfOt0V3sz8aV2I0RL1jSzj1gnDxNSPox4bgwZR6d+k3TY6UVbrOaf0Nq0caCZ:LfOtfV2IYSn1ASox3SR6dpTYbVbrrfcY

Entry address:
0x2723

Entry point:
BB, 24, E3, 5E, 20, 00, C7, 71, 04, 11, D8, 85, F6, B2, 4E, F7, C3, 5E, B7, A4, 2E, 0F, B7, C6, F7, C0, FA, 20, 2E, 1E, 53, 50, B2, F9, 8A, CC, F6, C1, 7E, E8, 9B, 00, 00, 00, 21, D9, 8A, C7, FF, CA, 33, D9, 84, D9, 38, FA, 81, F7, 2D, 8E, 00, 00, 80, F0, 81, 72, 01, F2, 8D, 05, 19, 0C, 45, 09, 81, FD, 9A, 9A, AD, 54, 88, F1, 0B, F6, 80, CC, 41, 88, CA, F7, C1, 9E, 79, 84, A7, 88, CE, B9, 97, 7A, 06, 00, 0F, B6, E8, 81, F1, 43, 3C, 00, 00, 88, F2, 81, F1, C3, 46, 06, 00, 80, D0, A7, 8D, 19, FE, C6, 6B, DB...
 
[+]

Entropy:
7.9992  (probably packed)

Code size:
36 KB (36,864 bytes)

The file msetup_x86.exe has been seen being distributed by the following URL.

Scan msetup_x86.exe - Powered by Reason Core Security