shrift-kassovogo-apparata-merkuriy-114.exe

Операционная система Microsoft Windows

Feniks Tekhniks, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable shrift-kassovogo-apparata-merkuriy-114.exe, “Исполняемый файл для игры "Mahjong Titans"” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Feniks Tekhniks, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Mahjong Titans"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
f30917c6e4f57c4da3ca52809cdecd6e

SHA-1:
cc72b29a84516c84c6c71ae02335083418244d58

SHA-256:
cfa45a8c1c7a711e841fc9e87799f49aea912a6e286a015c15db93e8e3fcd0d7

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
8/6/2025 9:08:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.20.14

File size:
2.7 MB (2,821,400 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
mahjong.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\shrift-kassovogo-apparata-merkuriy-114.rar\shrift-kassovogo-apparata-merkuriy-114.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/17/2016 10:00:00 AM

Valid to:
7/23/2017 9:59:59 AM

Subject:
CN="Feniks Tekhniks, TOV", OU=IT, O="Feniks Tekhniks, TOV", STREET="vul. Paustovskoho, 37", L=Kryzhanivka, S=Odeska, PostalCode=67562, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5C81C3A71C4D60F7AF7FBCE11853B06A

File PE Metadata
Compilation timestamp:
6/21/2014 2:06:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x5F980

Entry point:
6A, 70, 68, 80, 20, 46, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 0C, 20, 46, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 30, 20, 46, 00, 59, 83, 0D, 38, F0, 6B, 00, FF, 83, 0D, 3C, F0...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
387 KB (396,288 bytes)

Remove shrift-kassovogo-apparata-merkuriy-114.exe - Powered by Reason Core Security