abusb.exe

A bootable USB

My Little Soft - mylittlesoft.blogspot.com

This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from onedrive.live.com and multiple other hosts.
Publisher:
My Little Soft - mylittlesoft.blogspot.com

Product:
A bootable USB

Description:
A bootable USB

Version:
0.9.5.471

MD5:
1d4b312f7fae4ebab8dd20ea0f7be5b8

SHA-1:
08b97be98bf9d1554eb671098d40b50951088384

SHA-256:
1ea8c7869d8e2762eefe870d93bbd3d3e5c0df1f7ac4929f0cb4ac7c3edfdc52

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/25/2018 10:03:36 PM UTC  (today)

File size:
862.1 KB (882,814 bytes)

Product version:
0.9.5.471

Copyright:
My Little Soft - mylittlesoft.blogspot.com

File type:
Executable application (Win32 EXE)

Language:
Grego (Grécia)

Common path:
C:\users\{user}\downloads\abusb.exe

File PE Metadata
Compilation timestamp:
4/16/2010 4:47:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:H1qyeHypUsJiGFzeSTRlBs/B2/+C8jFOP:HdIyp7iGHBs/B2/CMP

Entry address:
0xC0210

Entry point:
60, BE, 00, 50, 48, 00, 8D, BE, 00, C0, F7, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 9B, E1, 0B, 00, 57, 83, C3, 04, 53, 68, 08, B2, 03, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 00, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
240 KB (245,760 bytes)

Scheduled Task
Task name:
{04F74E43-A1A8-4A15-87AF-74728F26F629}

Trigger:
Registration (Runs on registration)


The file abusb.exe has been seen being distributed by the following 14 URLs.

https://onedrive.live.com/download.aspx?cid=F52381D9F2FD5FD8&resid=F52381D9F2FD5FD8!535&canary=3k9boISZGSeBiMw9XODiDy1kdYkYjKaK2h8TbPPNf5s=1&ithint=.exe

https://onedrive.live.com/.../8WD79KNekl7lGQSTHF5I2xrRtQegr5efu6RFfrtE90=0&ithint=.exe

http://download846.mediafire.com/ciao61879amg/.../ABUSB.exe

http://download846.mediafire.com/sdnikgcc7zug/.../ABUSB.exe

http://download846.mediafire.com/1dyh5ixmcq5g/.../ABUSB.exe

https://onedrive.live.com/download.aspx?cid=F52381D9F2FD5FD8&resid=F52381D9F2FD5FD8!535&ithint=.exe

http://dl.dropbox.com/u/4666347/.../ABUSB.exe

https://onedrive.live.com/download.aspx?cid=F52381D9F2FD5FD8&resid=F52381D9F2FD5FD8!535

Scan abusb.exe - Powered by Reason Core Security