setup.x64.en-us_o365homepremretail_7ea7e5f6-b5c5-46e5-8330-5fafff70d8bd_tx_db_.exe

Microsoft Office 15

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Office 15

Description:
Microsoft Office Click-to-Run

Version:
15.0.4128.1014

MD5:
d8aa8ff01fe6632f15662d2813f18177

SHA-1:
c866c5225a0ece4dd806cebe399e120bef167034

SHA-256:
e48eeef4768b4a7753b0a1f90dba069cb0abe0ec953d4424f07f987adb93d29b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/24/2024 4:54:46 AM UTC  (today)

File size:
658.6 KB (674,416 bytes)

Product version:
15.0.4128.1014

Original file name:
Bootstrapper.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\setup.x64.en-us_o365homepremretail_7ea7e5f6-b5c5-46e5-8330-5fafff70d8bd_tx_db_.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
10/11/2011 4:32:25 AM

Valid to:
1/11/2013 4:32:25 AM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
6119CC93000100000066

File PE Metadata
Compilation timestamp:
6/23/2012 1:33:22 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
12288:bwY76oTneGbYKn30miIz37NGYs1KvUPaBLVp:bbrbP3nHLPzJT

Entry address:
0x377D0

Entry point:
48, 83, EC, 28, E8, 63, 53, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, 90, 90, E9, B7, 18, 00, 00, 90, 90, 90, 53, 48, 83, EC, 20, BA, 08, 00, 00, 00, 8D, 4A, 18, E8, 72, 54, 00, 00, 48, 8B, C8, 48, 8B, D8, FF, 15, 8E, 8B, 01, 00, 48, 89, 05, DF, 91, 05, 00, 48, 89, 05, D0, 91, 05, 00, 48, 85, DB, 75, 05, 8D, 43, 18, EB, 06, 48, 83, 23, 00, 33, C0, 48, 83, C4, 20, 5B, C3, 90, 90, 48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 48, 89, 7C, 24, 18, 41, 54, 41, 55, 41, 56, 48, 83, EC, 20, 4C, 8B, F1, E8, 53, 3F, 00...
 
[+]

Entropy:
6.0094

Code size:
312.5 KB (320,000 bytes)

The file setup.x64.en-us_o365homepremretail_7ea7e5f6-b5c5-46e5-8330-5fafff70d8bd_tx_db_.exe has been seen being distributed by the following 33 URLs.

http://www.tamindir.com/indir/MjAxNy0wMS0yNCAwNDoyNTo0MQ==/office-2013/windows/.../64-bit

http://www.tamindir.com/indir/MjAxNi0wOS0yMiAxNjoxNjo1MA==/office-2013/windows/.../64-bit

http://123.briian.com/forum.php?mod=attachment&aid=MTMzNnwzZDQxNWMzMHwxNDc2Nzk3NjAxfDB8NTAz

http://www.tamindir.com/indir/MjAxNi0xMi0wOSAxNTowNjoxMQ==/office-2013/windows/.../64-bit

http://www.tamindir.com/indir/MjAxNi0xMC0xMyAyMjo0NTowMg==/office-2013/windows/.../64-bit

http://depo.inddir.com/.../MicrosoftOffice2013HomePremium-64bit-inddir.exe

http://123.briian.com/forum.php?mod=attachment&aid=MTMzNnxkYjg1OTk0OXwxNDY4OTA1OTc2fDB8NTAz

http://123.briian.com/forum.php?mod=attachment&aid=MTMzNnw5OTY0MTQ2N3wxNDcyMjEzMzQ3fDB8NTAz

http://www.tamindir.com/indir/MjAxNi0xMC0zMSAyMToyNzowMA==/office-2013/windows/.../64-bit

http://www.tamindir.com/indir/MjAxNi0wOC0yMSAxNTozOTowMg==/office-2013/windows/.../64-bit

http://www.tamindir.com/indir/MjAxNi0xMC0yNiAxMjoxMTowNg==/office-2013/windows/.../64-bit

http://www.tamindir.com/indir/MjAxNi0wOS0wOCAwMToxMTo0OA==/office-2013/windows/.../64-bit

Latest 30 of 33 download URLs