isetting.exe

Navigation network co.,limited

The application isetting.exe by Navigation network co.,limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘isetting’. The file has been seen being downloaded from www.indirveoyna.com.
Publisher:
Navigation network co.,limited  (signed and verified)

MD5:
c561e64923ee893f7751388d651808d6

SHA-1:
6e80e760e15010cfca274be68a072f56f8b19955

SHA-256:
2bc85b73def330d739729eb157d6e65c2af5287335e2a878826160092d1168e3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 11:25:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Navigati (M)
16.7.1.14

File size:
2 MB (2,125,152 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\isetting.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/19/2014 2:00:00 AM

Valid to:
2/20/2016 1:59:59 AM

Subject:
CN="Navigation network co.,limited", OU=Software Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Navigation network co.,limited", L=Hongkong, S=Hongkong, C=HK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2617E71F3DD61639E291AD2D048E1D8A

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ju9enhOTG/nEmuqR9IGtvuO88lmT5c5PRNMNw:j0ehOG/0qQGtH88lGWRNMNw

Entry address:
0x1934DC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 2C, 2F, 59, 00, E8, F4, 3A, E7, FF, A1, 08, AD, 5A, 00, 8B, 00, E8, F4, 35, ED, FF, 8B, 0D, 58, AF, 5A, 00, A1, 08, AD, 5A, 00, 8B, 00, 8B, 15, 20, F7, 58, 00, E8, F4, 35, ED, FF, A1, 08, AD, 5A, 00, 8B, 00, E8, 68, 36, ED, FF, E8, 17, 11, E7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7074

Developed / compiled with:
Microsoft Visual C++

Code size:
1.6 MB (1,648,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
isetting

Command:
C:\Program Files\isetting.exe


The file isetting.exe has been seen being distributed by the following URL.

http://www.indirveoyna.com/.../isetting.exe

Remove isetting.exe - Powered by Reason Core Security