SOFFICE.EXE

Apache Software Foundation

It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from zalacznik.wp.pl and multiple other hosts.
Publisher:
Apache Software Foundation

Description:
OpenOffice 4.0.1

Version:
4.00.9714

MD5:
55f18be55d04a5cc961b0a013b2b8fd7

SHA-1:
8e3cc5661e16cf4bd003ed7e319974ce6524881b

SHA-256:
0877c2227e3c1200254f88ec7e08f05716a1bf121d3a348a4deab9f2053aec71

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:39:27 AM UTC  (today)

File size:
9.4 MB (9,837,056 bytes)

Product version:
4.00.9714

Copyright:
Copyright © 2000-2013 by Apache Software Foundation

Original file name:
SOFFICE.EXE

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\openoffice 4\program\soffice.exe

File PE Metadata
Compilation timestamp:
9/16/2013 7:21:39 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:D4adWhxSd/FUpoWyKAozKY4TPLKAoSKn:DjdWxu/mpodKACXCzKAfY

Entry address:
0x25C2

Entry point:
E8, DD, 04, 00, 00, E9, D8, FC, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 48, 41, 40, 00, 89, 0D, 44, 41, 40, 00, 89, 15, 40, 41, 40, 00, 89, 1D, 3C, 41, 40, 00, 89, 35, 38, 41, 40, 00, 89, 3D, 34, 41, 40, 00, 66, 8C, 15, 60, 41, 40, 00, 66, 8C, 0D, 54, 41, 40, 00, 66, 8C, 1D, 30, 41, 40, 00, 66, 8C, 05, 2C, 41, 40, 00, 66, 8C, 25, 28, 41, 40, 00, 66, 8C, 2D, 24, 41, 40, 00, 9C, 8F, 05, 58, 41, 40, 00, 8B, 45, 00, A3, 4C, 41, 40, 00, 8B, 45, 04, A3, 50, 41, 40, 00, 8D, 45, 08, A3, 5C, 41, 40...
 
[+]

Entropy:
4.9742

Code size:
7.5 KB (7,680 bytes)

Scheduled Task
Task name:
{026B29D0-1E2F-47DE-8632-7439E109AF13}

Trigger:
Registration (Runs on registration)


The file SOFFICE.EXE has been seen being distributed by the following 5 URLs.

http://zalacznik.wp.pl/0/.../soffice.exe

Scan SOFFICE.EXE - Powered by Reason Core Security