chromesetup.exe

LLC

The application chromesetup.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from 4d29a.needright.ru.
Publisher:
LLC   (signed and verified)

MD5:
82c2338fe6b194e011629997b653df54

SHA-1:
065eca94a89f47eac61981dc07d21bcd790bbb6a

SHA-256:
0566bcde5e6f8bf6994a336b12fb64a21e189b032995a0bd1df0e1c00b10a206

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 4:18:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize.Installer (M)
16.4.27.0

File size:
2 MB (2,148,816 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\chromesetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/27/2015 3:00:00 AM

Valid to:
5/27/2016 2:59:59 AM

Subject:
CN="LLC ""Ukrndikomunproekt""", O="LLC ""Ukrndikomunproekt""", STREET="vul. Sumska, 6", L=Kharkiv, S=Kharkivska, PostalCode=61057, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
67EE382F035CE763A8BF0617A055BB96

File PE Metadata
Compilation timestamp:
9/25/2010 9:30:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
49152:4P7ALxrWNXqsNXasmE25zDJvf1XhgHjhp3V46:e7AdWNXH8f7JJvfphgHrV46

Entry address:
0x1F8BD2

Entry point:
6A, 28, 68, C0, 93, 5F, 00, E8, 92, 01, 00, 00, 33, FF, 57, FF, 15, 7C, 91, 5F, 00, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 01, FF, 15, 3C, 93, 5F, 00, 59, 83, 0D, 68, C1, 7F, 00, FF, 83, 0D, 6C, C1, 7F, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
2 MB (2,063,872 bytes)

The file chromesetup.exe has been seen being distributed by the following URL.

Remove chromesetup.exe - Powered by Reason Core Security