app_setup.exe

Program Application

DMN Partners SRL

The application app_setup.exe, “Program Application Setup ” by DMN Partners SRL has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.bitsvaultsquick.com.
Publisher:
Internet Installer   (signed by DMN Partners SRL)

Product:
Program Application

Description:
Program Application Setup

Version:
3.0.3.1

MD5:
3e25f854562a26ab8c28f2d805c0ed84

SHA-1:
3e620ac865afa38fe57fb31c3703471ea32821d8

SHA-256:
bc5b4c11f9c02f20239f1ab9d5bf5e27414cbd5feea76ec77c7b53d19778b343

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 9:46:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.DMNPartners.Installer (M)
16.1.8.3

File size:
900.3 KB (921,872 bytes)

Product version:
1.1.9

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\app_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/11/2015 9:00:00 PM

Valid to:
6/11/2016 8:59:59 PM

Subject:
CN=DMN Partners SRL, O=DMN Partners SRL, STREET=Str Liviu Rebreanu 46-58, L=Bucharest, S=District 3, PostalCode=031793, C=RO

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3EB036A1CA66096F2715D12685C107F3

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:3mg02ibS84oeVceOLnzlyPDXrFbKoRAudimrnPF:3t2R4HOM1KoRAudPPF

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file app_setup.exe has been seen being distributed by the following URL.

Remove app_setup.exe - Powered by Reason Core Security