VirusShare_c091893cb64e1b62a833e5e8660d5b7a
PE
Verdict: BENIGN
Objectives
-
Software\C -
Software\M -
VS_VERSION_INFO
-
F:\Office\Targetd\ship\postc2r\xone\msoxmled.pdb
-
F:\Office\Targetd\ship\postc2r\xone\msoxmled.pdb -
\msoxmled.pdb -
msoxmled.pdb
-
ClearPropertyBagValue -
GetStatusValue -
RegQueryValueExW
-
5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 -
Microsoft Corporation -
Microsoft Corporation0 -
Microsoft Corporation1 -
Microsoft Corporation1!0 -
Microsoft Corporation1#0! -
Microsoft Corporation1&0$ -
Microsoft Corporation1(0&
-
IsRoaming
-
WinWord
Micro-behaviors
-
URLDownloadToFileW -
WININET.dll -
urlmon.dll
-
Microsoft Code Signing PCA 2011 -
Microsoft Time-Stamp PCA 2010 -
Microsoft Time-Stamp Service
-
GetProcAddress
-
CreateFile
-
IsWow64Process
-
ADVAPI32.dll -
SHELL32.dll -
USER32.dll
-
RegQueryValueExW
-
CloseHandle -
CreateProcessW
Metadata
-
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 -
Microsoft Corporation -
VirusShare_c091893cb64e1b62a833e5e8660d5b7a
-
parse.error_count = 2.00
-
Microsoft Corporation×3 -
CN=Microsoft Code Signing PCA,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US -
Microsoft Code Signing PCA 2011 -
Microsoft Time-Stamp PCA 2010 -
Microsoft Time-Stamp Service -
true
-
[high_entropy_va, dynamic_base, nx_compat, terminal_server_aware]×3
-
= 0.0% of total (0 / 234004 bytes)
20 of 28 traits shown
Objectives
-
Software\C -
Software\M -
VS_VERSION_INFO
-
F:\Office\Targetd\ship\postc2r\xone\msoxmled.pdb
-
F:\Office\Targetd\ship\postc2r\xone\msoxmled.pdb -
\msoxmled.pdb -
msoxmled.pdb
-
ClearPropertyBagValue -
GetStatusValue -
RegQueryValueExW
-
5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 -
Microsoft Corporation -
Microsoft Corporation0 -
Microsoft Corporation1 -
Microsoft Corporation1!0 -
Microsoft Corporation1#0! -
Microsoft Corporation1&0$ -
Microsoft Corporation1(0&
-
IsRoaming
-
WinWord
Micro-behaviors
-
URLDownloadToFileW -
WININET.dll -
urlmon.dll
-
Microsoft Code Signing PCA 2011 -
Microsoft Time-Stamp PCA 2010 -
Microsoft Time-Stamp Service
-
GetProcAddress
-
CreateFile
-
IsWow64Process
-
ADVAPI32.dll -
SHELL32.dll -
USER32.dll
-
RegQueryValueExW
-
CloseHandle -
CreateProcessW
Metadata
-
4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 -
Microsoft Corporation -
VirusShare_c091893cb64e1b62a833e5e8660d5b7a
-
parse.error_count = 2.00
-
Microsoft Corporation×3 -
CN=Microsoft Code Signing PCA,O=Microsoft Corporation,L=Redmond,ST=Washington,C=US -
Microsoft Code Signing PCA 2011 -
Microsoft Time-Stamp PCA 2010 -
Microsoft Time-Stamp Service -
true
-
[high_entropy_va, dynamic_base, nx_compat, terminal_server_aware]×3
-
= 0.0% of total (0 / 234004 bytes)
20 of 28 traits shown
Identity
| SHA-256 | 926afd83eed59afe5167246effc0f82c27d7567ff4b9f9642cb2378dd3acbe3d |
|---|---|
| Filename | VirusShare_c091893cb64e1b62a833e5e8660d5b7a |
Timeline
| First seen | 12 May 2026 19:04 UTC |
|---|---|
| Last analyzed | 24 May 2026 02:11 UTC |
Not seeing what you expected? Let us know