finaltorrentsetup.exe

Sak

Locat

The application finaltorrentsetup.exe, “Sak Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Locat

Product:
Sak

Description:
Sak Setup

MD5:
12813376d45331e4da976ffea63bf1e4

SHA-1:
09cc9501e8e41f1e3d022adebe8ab2d780f14e88

SHA-256:
8168fdb9587fd37411d0e75d0a8fce7f7ee5bbbbbdd62cb47394c3df75de1306

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 3:37:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.11 (M)
16.3.6.11

File size:
1.1 MB (1,164,316 bytes)

Product version:
3.2.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\finaltorrentsetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:uCzSuQK2mOouEq50eNKMp7hkats2COTy7WlhJ0FzGjdD5wc8oyQTd4XT4j1jl0w2:uCzMK2mOo0TgAkaS2vnl7Sz0dFwrb843

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file finaltorrentsetup.exe has been seen being distributed by the following 42 URLs.

http://www.giftbinariestowers.com/c?x=WBLAEWPpALG3xFrfXBcCSQihxXt0NF8wj9L07N4SefQ=&c=agXi4CywRi8wcc/M6ks5dsmtBCowxDPkGm7vYKdQqFGEetPbz43V0W/5iWmzV8cGONNwWYXM/5ajJNgMAe3VQDFoUikdtI1 sCSooqPn76wfQsPARTk CVPw1w2aFb2VJv1DVDYCKV9APXVmHrlTdMTrDW3affQzUU2AlwW9yQlDuLvaV20ZSwK4MfSl2Xum&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.farmapplicationbits.com/c?x=w6nxpTYk37J61M4RN2ShNST3pxI TLn1Z8UZyVVWfGA=&c= e9dZR5fTNTyDwTdaTdqVTNhr3 na3w5k9Zbh7iy2CFBD RdvuhivL7EaquMwKOx/41sdgl V33jK4zfOFPkajD2PLDIvVNYrdYIzOejVh8HrtAwnRwW5p/1JdFIL iX/DvvOjfe0tOtitgs60Vw1zyaMUQdxeOCc7o0F8OupEpPatoGFX9q Xkorc84Hq6j&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.giftbinariestowers.com/c?x=7lnYZEA2TCxpODJJ32B9Dy1l3PLGMeyimcLvCsacx0s=&c=71bJbpTtre7CE2IxlDBpr/UeLhZJirOoNSxaBZdMSSMMwFTcNvS1xHTqzwa6O5SSg Pzpi K1EY8BBvEnypCNGIzUGzBpcvG/u4QUR//njCImnjhTQsBP/U90umgvEMDUaUEK7AKuhG6LX4zTB 9mlR347v7yxuKONyaVECwXp3 WtD6p3bPcIL4Mqd5pM52&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.giftbinariestowers.com/c?x=BiN9zGWNnoX8pj6m6M0g3Kx3bL7qq/JyyljAUhOiG/0=&c=XYjSuArT /jryFfajdF5B0Vy/7q7OZlBWdOz0NvvyW6WdAYBF93OW/QKXvawe6mv0pW4ZaHrI5vwBjduc/AsLK5iXqPmN4Piqk2h46Pyluo3T5DFNbTFA4dKBDuzH5WH/jfV/MJrGJnFvYOeuarYjb48LhHVkGACqXi65cTeYVtnPUHcTBZ3OexoAZ2oJD/j&e=0&downloadAs=FinalTorrentSetup.exe&fallback_url=http://www.finaltorrent.com/.../newest.exe

http://www.vaultappsranch.com/WVl6OTRQV0o2Tm05UFUyMUVURXhyYTFaUWJFdFFKVEpDVkVGYVVUSlVUWFJoVmpjMkpUSkdaazU1ZW1aNWNURllPRTVCSlRORUptTTlRMmgyUW1GcE4zbHBXRlJxYVdWaU0yZDNlSGxKVFhCQ2VpVXlSa05IUVhoVFpWQmlNVXBhV2toM1pqVkhZMEpsZVRoTFJYY3dXV0Z4YUdvd2RUVnhObGhZU1hKRFJITTBiblY0Y3pSc1EyTnFNM2hxYzA0d1Eyd3pUakJsV1VWWlRsRkZZMnB6VlRreVZERkplV3A1T0VzeVozWndOMGczVmxKR2RsUjZjV1Z1YzJWdlJVbDJjMFJ1UWxKUVFrVkxhMU51TWpoV1JrRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05Um1sdVlXeFViM0p5Wlc1MFUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbVpwYm1Gc2RHOXljbVZ1ZEM1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadVpYZGxjM1F1WlhobA==

Latest 30 of 42 download URLs

Remove finaltorrentsetup.exe - Powered by Reason Core Security