duetsetup-1-4-5-4.exe

Duet Display

Kairos Technologies, Inc.

This is a self-extracting archive and installer. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘{52444E6D-BBB3-4BC1-A4E3-3602B173BB42}’. The file has been seen being downloaded from www.google.com and multiple other hosts.
Publisher:
Kairos  (signed by Kairos Technologies, Inc.)

Product:
Duet Display

Description:
This installer database contains the logic and data required to install Duet Display.

Version:
1.4.5.4

MD5:
9486dbf981a6a4eeba4f7e4b2c5ad975

SHA-1:
e4e7497dd7abecef1be3d00c437a479efc7d7974

SHA-256:
1a935270a7c375de065497f8a968a1c5000adf5fa8cb02a34807c7fd214cee80

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
2/25/2025 7:26:34 PM UTC  (today)

File size:
131.3 MB (137,707,320 bytes)

Product version:
1.4.5.4

Copyright:
Copyright (C) 2016 Kairos

Original file name:
DuetSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\duetsetup-1-4-5-4.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
4/23/2015 2:00:00 AM

Valid to:
4/26/2018 2:00:00 PM

Subject:
CN="Kairos Technologies, Inc.", O="Kairos Technologies, Inc.", L=Miami, S=Florida, C=US, PostalCode=33131, STREET=325 S Biscayne Blvd, STREET=UPH 17, SERIALNUMBER=P15000001077, OID.1.3.6.1.4.1.311.60.2.1.2=Florida, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09F6D17ADBD7197A188DC6E64D8998D7

File PE Metadata
Compilation timestamp:
12/14/2016 12:20:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0xCC1F8

Entry point:
E8, 3E, 06, 00, 00, E9, 8E, FE, FF, FF, FF, 25, 98, 52, 51, 00, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 7A, 07, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 64, 07, 00, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 8B, 4D, F0, 33, CD, F2, E8, 7E, F4, FF, FF, F2, E9, DA, FF, FF, FF, 8B, 4D, EC, 33, CD, F2, E8, 6D, F4, FF, FF, F2, E9, C9, FF, FF, FF, 50, 64, FF, 35, 00...
 
[+]

Code size:
1.1 MB (1,129,472 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
{52444E6D-BBB3-4BC1-A4E3-3602B173BB42}

Command:
"C:\users\{user}\downloads\duetsetup-1-4-5-4.exe" \cmdloc "hkcu\software\kairos aitemp\{52444e6d-bbb3-4bc1-a4e3-3602b173bb42}"


The file duetsetup-1-4-5-4.exe has been seen being distributed by the following 2 URLs.

https://www.google.com/url?hl=en&q=http://.../windows&source=gmail&ust=1482642571856000&usg=AFQjCNFYqTZuk2ECKSGrzazQ4RiwsTmk8A

https://www.duetdisplay.com/windows

Scan duetsetup-1-4-5-4.exe - Powered by Reason Core Security