direct-x-9.exe

Ultra Setup Manager

Husren SA

Publisher:
MS  (signed by Husren SA)

Product:
Ultra Setup Manager

Version:
1.0.3.21

MD5:
ff3a14b20c5bad79e0ffd9bdadb15052

SHA-1:
b7ccdc417bf3a5dba7c59904a6f42b9bcc9fa020

SHA-256:
17546b572795f6bc9dd4c9d43de7592a3476379060fdecdaac9aa1a6382b4657

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:33:40 AM UTC  (today)

File size:
30.1 KB (30,824 bytes)

Product version:
1.0.3.21

Copyright:
Copyright © 2015

Trademarks:
MS

Original file name:
iEx.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\direct-x-9.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/12/2015 7:00:00 AM

Valid to:
6/12/2016 6:59:59 AM

Subject:
CN=Husren SA, OU=602, O=Husren SA, STREET=Colonia 810 esc502, L=Montevideo, S=Montevideo, PostalCode=11000, C=UY

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
13D29ADB2F499B625116D9BBF3D8B83F

File PE Metadata
Compilation timestamp:
8/28/2015 8:30:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
192:LjComX0M9u2y/rs200d5IyMrj1g6g2PmbbhXH87uGauospvxSsH:6omX0M9ul/rs200ddMaTriZ

Entry address:
0x2EEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5086

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4 KB (4,096 bytes)

The file direct-x-9.exe has been seen being distributed by the following 2 URLs.

http://develop2repo.com/getAd.php?f=iEx.exe&fc=adobe-flash-player.exe

Scan direct-x-9.exe - Powered by Reason Core Security