defaulttabsetup.exe

Search Results, LLC

The application defaulttabsetup.exe by Search Results has been detected as adware by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.airdlr8.com and multiple other hosts.
Publisher:
Search Results  (signed by Search Results, LLC)

Description:
Setup.exe

Version:
2.3.5.0

MD5:
5b773c76a0f9d0a8e7d16c8e052df707

SHA-1:
0209c34cae189ab91d3e2e2b0c68341eca203f78

SHA-256:
30dc8db254fc558c17b53f91ff4ce6ac90419254ef9b0187b8e4adf769cfae00

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
11/23/2024 4:03:10 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod091.Trojan
1.3.0.4613

Boost by Reason
Optional.SearchResults.P
188838

Dr.Web
Adware.Plugin.48
9.0.1.0104

ESET NOD32
Win32/Toolbar.DefaultTab (variant)
8.9190

K7 AntiVirus
Unwanted-Program
13.174.10656

Malwarebytes
PUP.Optional.DefaultTab.A
v2014.04.14.07

McAfee
Artemis!B2D361D6CCFC
5600.6995

NANO AntiVirus
Riskware.Win32.Plugin.crfhgu
0.28.0.59048

Reason Heuristics
PUP.Installer.SearchResults.P
14.8.7.17

Sophos
Generic PUA BM
4.96

File size:
3 MB (3,143,792 bytes)

Product version:
2.3.5.0

Copyright:
Search Results, LLC

Trademarks:
Search Results, LLC

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\4b337c66319340abb1da7ada36abef5d\software\defaulttabsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/24/2012 7:00:00 PM

Valid to:
4/25/2014 6:59:59 PM

Subject:
CN="Search Results, LLC", O="Search Results, LLC", STREET="2751 Hennepin Ave S #252", L=Minneapolis, S=MN, PostalCode=55405, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B6815DF3B6D64839E008D65B53EF0170

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:bgjdEC4CMatdVh7ujvYbShgqrHrTQKFSajQRRVMGfR/Mop/CfI0ZEJhIjhf1gEj9:ry1Bbi7r3D7jQRPMGJ5p/GUfAfqgOfC

Entry address:
0x647001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, 70, 64, 00, 83, BD, 88, 04, 00, 00, 00, 89, 9D, 88, 04, 00, 00, 0F, 85, CB, 03, 00, 00, 8D, 85, 94, 04, 00, 00, 50, FF, 95, A9, 0F, 00, 00, 89, 85, 8C, 04, 00, 00, 8B, F0, 8D, 7D, 51, 57, 56, FF, 95, A5, 0F, 00, 00, AB, B0, 00, AE, 75, FD, 38, 07, 75, EE, 8D, 45, 7A, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 56, 69, 72, 74...
 
[+]

Entropy:
7.9981

Packer / compiler:
ASPack v2.12

Code size:
1.4 MB (1,481,216 bytes)

The file defaulttabsetup.exe has been seen being distributed by the following 2 URLs.

Remove defaulttabsetup.exe - Powered by Reason Core Security