citriosetup.exe

CatalinaGroup Update

Catalina Group Limited

The application citriosetup.exe, “CatalinaGroup Update Setup” by Catalina Group Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from catalinahub.com.
Publisher:
Catalina Group Ltd.  (signed by Catalina Group Limited)

Product:
CatalinaGroup Update

Description:
CatalinaGroup Update Setup

Version:
1.3.25.223

MD5:
80be64b2fa490252e597fe877f2f5d41

SHA-1:
9c7a2916ae7a84df6aefa5f9fb103243b6d6ec17

SHA-256:
5677e7a5671634c8d809ca85b7cd36ef2bc06e193e2bf958d18f01d3c901ef39

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 4:49:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Catalina (M)
16.8.10.23

File size:
707.6 KB (724,536 bytes)

Product version:
1.3.25.223

Copyright:
Copyright 2013 Catalina Group Ltd.

Original file name:
CatalinaUpdateSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\citriosetup.exe

Digital Signature
Authority:
Starfield Technologies, Inc.

Valid from:
1/12/2015 3:36:38 PM

Valid to:
9/27/2016 5:56:54 AM

Subject:
CN=Catalina Group Limited, O=Catalina Group Limited, L=Kwun Tong, S=Hong Kong, C=HK

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
1855136D47C1A483

File PE Metadata
Compilation timestamp:
10/10/2015 7:18:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:alARGOhU6FbKqeDPsxKyMuLzuMoPAbZaQ/kx6TOwKhSgzGYSsCGXLL:aigOhZ53euKd2IEZdkyOwKw0GY

Entry address:
0x49AA

Entry point:
E8, FD, 15, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 52, 16, 00, 00, 33, C0, 5D, C2, 04, 00, 68, B4, 49, 40, 00, FF, 15, 08, D0, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 57, BF, E8, 03, 00, 00, 57, FF, 15, 10, D0, 40, 00, FF, 75, 08, FF, 15, 0C, D0, 40, 00, 81, C7, E8, 03, 00, 00, 81, FF, 60, EA, 00...
 
[+]

Entropy:
7.5806

Code size:
46.5 KB (47,616 bytes)

The file citriosetup.exe has been seen being distributed by the following URL.

Remove citriosetup.exe - Powered by Reason Core Security