usetting.exe

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘usetting’. The file has been seen being downloaded from www.guzel.net.
MD5:
4d48d1ca14029ae3587c5adebad6f9e4

SHA-1:
cc08cef6b4407c4bf346b825da786fb08220afac

SHA-256:
c74eac1d4e5ac8bfb475501e303d3795b923dcfcd64c9a154ffd848c25afe608

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 6:19:31 AM UTC  (today)

File size:
842 KB (862,208 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\usetting.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:gDwVqZx4E176GL9k1t2JEuGoU40o30eM7sI3L0vmN:gD6vEQGJk1tWsoeoE77s0N

Entry address:
0x2123B0

Entry point:
60, BE, 00, A0, 55, 00, 8D, BE, 00, 70, EA, FF, C7, 87, A0, 30, 19, 00, 0F, 08, 47, AA, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
740 KB (757,760 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
usetting

Command:
C:\Program Files\usetting.exe


The file usetting.exe has been seen being distributed by the following URL.

Scan usetting.exe - Powered by Reason Core Security