usagetemp.exe

White Sea Media

The application usagetemp.exe by White Sea Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘UsageTemp’. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from downloads.exoinstall.com.
Publisher:
White Sea Media  (signed and verified)

MD5:
ea5991a6793f22f085676d7f81beb882

SHA-1:
96c7a4bc498aba7362c437cedfafa63dedb44790

SHA-256:
dcf4d812d8ea1287ba57c1323c87afd14ddd004cd5ef623f138620e0fa94c4c0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 3:36:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WhiteSeaMedia (M)
16.2.9.18

File size:
1.2 MB (1,260,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\usagetemp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/8/2013 2:00:00 AM

Valid to:
7/9/2014 1:59:59 AM

Subject:
CN=White Sea Media, O=White Sea Media, STREET=4142 Mariner Blvd, L=Spring Hill, S=FL, PostalCode=34609, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FB235ACA7565BA27ADC702B2BD05C7F

File PE Metadata
Compilation timestamp:
3/20/2014 6:55:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:VSACpzGYrvs5HmMjEmM4r2jQOFxVuZ77SYibGE1o7KjA:VG7sHNvO3MZ76N1o7KU

Entry address:
0x326000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 70, 12, 00, 2D, FF, 91, 0A, 10, 05, F4, 91, 0A, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 48, E8, C3, 5C, 68, 4B, 96, C5, 1B, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 45, AB, 30, 3B, 51, A6, 78, AE, 92, EA, A0, FC, A0, D1...
 
[+]

Code size:
47.5 KB (48,640 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
UsageTemp

Command:
"C:\users\{user}\appdata\local\temp\usagetemp.exe"


The file usagetemp.exe has been seen being distributed by the following URL.

Remove usagetemp.exe - Powered by Reason Core Security