setup.x86.nb-no_o365proplusretail_9909de81-729f-4795-a068-ccd2757a0cf1_tx_pr_.exe

Microsoft Office

Microsoft Corporation

This is a setup program which is used to install the application. The file has been seen being downloaded from c2rsetup.officeapps.live.com and multiple other hosts.
Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft Office

Description:
Microsoft Office Klikk og bruk

Version:
15.0.4787.1002

MD5:
f3143990fffcf7a62189c0f405b2b5ff

SHA-1:
f8b122aef7f4d0284d503a2aef7eed9c596080e4

SHA-256:
5a29f033dde42f24bb3b4789b7375560f2c785dcdc2f167b4a11e2a68c936156

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
4/27/2024 12:06:28 AM UTC  (today)

File size:
1.1 MB (1,104,576 bytes)

Product version:
15.0.4787.1002

Original file name:
Bootstrapper.exe

File type:
Executable application (Win32 EXE)

Language:
Norsk bokmål (Norge)

Common path:
C:\users\{user}\downloads\setup.x86.nb-no_o365proplusretail_9909de81-729f-4795-a068-ccd2757a0cf1_tx_pr_.exe

Digital Signature
Authority:
Microsoft Corporation

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
330000010A2C79AED7797BA6AC00010000010A

File PE Metadata
Compilation timestamp:
12/23/2015 6:14:45 AM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.10

CTPH (ssdeep):
24576:4AdmaIi6VkH0lv8PWTKHW5uWev07Nq/Ed9xysJ/0qTsd:4AdmaHCQmV5uW2P/2bysJJW

Entry address:
0x5FCDD

Entry point:
E8, 5D, 53, 00, 00, E9, 81, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 95, 10, 00, 00, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 35, E4, 12, 40, 00, 57, FF, 35, 68, 9E, 4E, 00, FF, D6, FF, 35, 64, 9E, 4E, 00, 8B, D8, 89, 5D, FC, FF, D6, 8B, F0, 3B, F3, 0F, 82, 81, 00, 00, 00, 8B, FE, 2B, FB, 8D, 47, 04, 83, F8, 04, 72, 75, 53, E8, 87, 54, 00, 00, 8B, D8, 8D, 47, 04, 59, 3B, D8, 73, 48, B8, 00, 08, 00, 00, 3B, D8, 73, 02, 8B, C3, 03, C3, 3B, C3, 72, 0F, 50, FF, 75, FC, E8, 15, 54, 00, 00, 59, 59, 85, C0, 75, 16, 8D...
 
[+]

Code size:
888.5 KB (909,824 bytes)

The file setup.x86.nb-no_o365proplusretail_9909de81-729f-4795-a068-ccd2757a0cf1_tx_pr_.exe has been seen being distributed by the following 30 URLs.

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-NO&TaxRegion=pr&correlationId=f5e3f8b6-6669-4312-84c6-cbb055438019&token=55b38c9e-d2d8-4571-b228-0d17c24a9f1c&version=O15GA&source=O15OLSO365&B=0

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-no&TaxRegion=pr&correlationId=176be141-8835-4c78-90a7-e2b1037ca2bd&token=46084d80-73d2-4922-b789-e53a55ca8b91&version=O15GA&source=O15OLSO365

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-NO&TaxRegion=pr&correlationId=dc621aba-3320-4f33-b0b9-0ba9868ecd42&token=448e340c-22da-4e43-9f81-72eb07d70b67&version=O15GA&source=O15OLSO365&B=3

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-NO&TaxRegion=pr&correlationId=a1d7e67c-c207-4b01-911c-be270427091e&token=7a9c0459-2c7f-42c1-be15-f097a2a0e62f&version=O15GA&source=O15OLSO365&B=3

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-NO&TaxRegion=pr&correlationId=b7d5415f-5fbe-410c-b0e4-928dadd1f53f&token=a8283804-6365-463a-ae66-4e7e66b1af6f&version=O15GA&source=O15OLSO365&B=3

https://c2rsetup.officeapps.live.com/.../download.aspx?productReleaseID=O365ProPlusRetail&platform=X86&language=nb-NO&TaxRegion=pr&correlationId=c866500c-6544-4e6f-aa34-1d0ba537e4cd&token=43de73fc-4b2d-4181-a582-5101d5cde96c&version=O15GA&source=O15OLSO365&B=0

Latest 30 of 30 download URLs