handysetup_v3.exe

Ates Yazilim, Bilgisayar & Internet Teknolojileri Tic Ltd Sti

This is a setup program which is used to install the application. The file has been seen being downloaded from www.traidnt.net and multiple other hosts.
Version:
3.3.0.0

MD5:
f6410c1108a6f5b86599fa18b85f98f1

SHA-1:
8abef785e53b88aad5853ff65503af6a8e7989bf

SHA-256:
08d4f5c1fdf5a959dd0170b749e92cf08a30fabe310f0b03034dbdba605fc4a3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 7:20:51 PM UTC  (today)

File size:
13.4 MB (14,038,888 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\{random}\handysetup_v3.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/14/2012 2:00:00 AM

Valid to:
5/9/2013 1:59:59 AM

Subject:
CN="Ates Yazilim, Bilgisayar & Internet Teknolojileri Tic Ltd Sti", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Ates Yazilim, Bilgisayar & Internet Teknolojileri Tic Ltd Sti", L=Istanbul, S=Istanbul, C=TR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
75224E6FFA6A13A60DAFE010B6ACF4A8

File PE Metadata
Compilation timestamp:
1/24/2013 2:25:58 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:oed/nwK54vwduOttNRaEYIjnndO6S/4gq3fdTDBKkpRc/+eaL2u0GGoi6BY9BuZ:oHhvwdmE1bdWqvxBKkfcQLTCNoz

Entry address:
0x1837F8

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, B8, E0, 95, 57, 00, E8, 1A, 72, E8, FF, 8B, 1D, 34, E9, 58, 00, 6A, 00, 68, B8, 38, 58, 00, E8, 48, AE, E8, FF, 85, C0, 0F, 97, C0, 84, C0, 74, 15, 6A, 30, 68, D8, 38, 58, 00, 68, E4, 38, 58, 00, 6A, 00, E8, AC, B0, E8, FF, EB, 74, 8B, 03, E8, 0F, 1C, FA, FF, 6A, 00, 8B, 03, 8B, 80, 78, 01, 00, 00, 50, E8, 43, B2, E8, FF, 8B, 03, 8B, 80, 78, 01, 00, 00, BA, EC, FF, FF, FF, 52, 50, E8, D7, B4, E8, FF, 8B, 13, 8B, 92, 78, 01, 00, 00, BE, EC, FF, FF, FF, 25, FF, FF, FB, FF, 0D...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,583,616 bytes)

The file handysetup_v3.exe has been seen being distributed by the following 25 URLs.

http://www.traidnt.net/vb/safety_link.php?url=http://files.handycafe.com/.../HandySetup_v3.exe

http://handycafe-client.software.informer.com/.../

http://www.downloadcollection.com/downloadredirect.php?idx=139541

Scan handysetup_v3.exe - Powered by Reason Core Security