setup_dfstd.exe

The program is a setup application that uses the Nullsoft Scriptable Install System installer. The file has been seen being downloaded from doc-0o-1g-docs.googleusercontent.com.
MD5:
59697033697234fff797d20ac96546ac

SHA-1:
9a013d77850bb51fe4e114db781e7120f87ec34a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:28:26 AM UTC  (today)

File size:
5.9 MB (6,169,649 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\Documents and Settings\{user}\My documents\downloads\setup_dfstd.exe

File PE Metadata
Compilation timestamp:
12/6/2009 2:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:4MIzUZD+ImNSmMMimsvcF+GAfS5LnedXqvAMR6/d6U3CNnKwH:4zUB+ImNSmymLF+khsXqvA0IQUyNntH

Entry address:
0x30FA

Entry point:
FE, CD, 19, FE, 89, F5, 69, DD, D9, 83, 59, 03, F6, C3, DC, B1, 7D, 69, D5, F0, B0, 4D, DB, 48, 41, 28, E1, 8B, FA, 1B, C5, BA, 45, 9E, BE, 34, 88, C0, 56, C7, C7, 72, 63, 19, 44, 0F, B7, FF, F7, C3, 28, CC, 93, 07, 15, 21, 67, DE, 85, 3B, ED, E8, 00, 00, 00, 00, B8, D3, D2, 12, 7C, 8D, 3D, 59, D2, A5, EC, 08, D0, 69, D6, AF, CF, 86, A6, F7, C3, 11, 9A, BC, E1, 81, FB, DA, 9C, 00, 00, 58, F3, 8D, 2D, 42, D1, FC, D1, 68, B5, 99, 9A, 00, 89, CB, F6, C7, 96, F7, C1, 39, 22, 1F, 85, F2, 87, D2, B2, DB, 0F, BF...
 
[+]

Entropy:
7.8988  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file setup_dfstd.exe has been seen being distributed by the following URL.

Scan setup_dfstd.exe - Powered by Reason Core Security