epicsetup.exe

Epic Privacy Browser Update

Hidden Reflex

This is a self-extracting archive and installer. The file has been seen being downloaded from www.currentupdateconcepts.com and multiple other hosts.
Publisher:
Epic Privacy Browser  (signed by Hidden Reflex)

Product:
Epic Privacy Browser Update

Description:
Epic Privacy Browser Update Setup

Version:
1.3.27.5

MD5:
abbd31ccac40b80aa731377c8619f06e

SHA-1:
6808107177dd72b2529a153713e9e199d9274ef4

SHA-256:
a85cd8bad43e6c15f533d223b22736d10386a6767fbfc1c5c9b8db9cda43e168

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/15/2024 3:33:25 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V1013
7.2.132

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
22540

File size:
1.7 MB (1,831,576 bytes)

Product version:
1.3.27.5

Copyright:
Copyright 2007-2010 Google Inc.

Original file name:
EpicUpdateSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\epicsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/22/2013 1:00:00 AM

Valid to:
8/23/2014 12:59:59 AM

Subject:
CN=Hidden Reflex, O=Hidden Reflex, STREET=5744 Yewing Way, L=Gainesville, S=VA, PostalCode=20155, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A0B0D9AAAE8562F0CE35F0CA297D2005

File PE Metadata
Compilation timestamp:
10/12/2013 11:06:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:naEzvpm7zvfiGiNRshgXxH9I4fFstSYukKMwEG:aEqzvfiGiwhglS4d+1MEG

Entry address:
0x1000

Entry point:
8B, FF, 55, 8B, EC, E8, 36, 03, 00, 00, E8, 11, 00, 00, 00, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 6A, FE, 68, 20, 26, 46, 00, 68, D0, 70, 40, 00, 64, A1, 00, 00, 00, 00, 50, 83, C4, 94, 53, 56, 57, A1, 78, 40, 46, 00, 31, 45, F8, 33, C5, 50, 8D, 45, F0, 64, A3, 00, 00, 00, 00, 89, 65, E8, C7, 45, 90, 00, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, 8D, 45, A0, 50, FF, 15, 84, 31, 45, 00, C7, 45, FC, FE, FF, FF, FF, EB, 26, B8, 01, 00, 00, 00, C3, 8B, 65, E8, C7...
 
[+]

Entropy:
7.8057  (probably packed)

Code size:
325.5 KB (333,312 bytes)

The file epicsetup.exe has been seen being distributed by the following 2 URLs.

http://www.currentupdateconcepts.com/b 8_mnhuk_Yy7FkLWG6 XX6cOzF5DDinWuCeFNhHOlo28KAk3FuWH_SRqSVAKVe42znQpEYcjNdFGGSsJNOukC_CeHxXh_YijfOryQnIkczg3dJ7jgPG9xNaS9zkhL40g_MQ9 i5LPuobFa3bDxOwf0WMe_d0vk_r8P3eg0WQmSzp0CAKoHAnr8MrHL4AvwVJpBu5ulL-G0YAAARqbjHBl0RIhsgu0F6nm CQA4cvvEYWiIQcslK_CTRZ425TpOHeMsLTIRiQKtTlqDy9uM_JBw==

Scan epicsetup.exe - Powered by Reason Core Security