flux-setup.exe

Michael Herf

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from lb.cdn.m6web.fr and multiple other hosts.
Publisher:
Michael Herf  (signed and verified)

MD5:
097aa1113bf9c60994c2425c7547b760

SHA-1:
74f004c22d05479a6dc38b80841634ec3981c3f4

SHA-256:
99f6a5fcf8c6789ff4d69a98b6cb1af9296a76f210c01a6c8a0716ef79134f2f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 3:35:39 AM UTC  (today)

File size:
583.3 KB (597,304 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flux-setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/3/2012 7:00:00 PM

Valid to:
5/4/2014 6:59:59 PM

Subject:
CN=Michael Herf, O=Michael Herf, STREET=929 S. Gretna Green Way, L=Los Angeles, S=CA, PostalCode=90049, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F44D90F5015B431315399BB0349396EC

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:YX5NpKKrETxnxDWsMtGgvYGW621SMSTyte0eO9aVz2I8qCgQ:YX5NdMxkfBYt6CSfetveOE2I8qCgQ

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9496

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file flux-setup.exe has been discovered within the following programs.

Acoustica Mixcraft 6  by Acoustica, Inc
Publisher's description - “Mixcraft 6 is a powerful music production and multi-track recording workstation that comes packed with thousands of music loops and dozens of audio effects and virtual instruments.”
www.acoustica.com
9% remove it
F.lux  by justgetflux
Publisher's description - “f.lux fixes this: it makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day. It's even possible that you're staying up too late because of your computer. You could use f.”
stereopsis.com/flux
4% remove it
Toolwiz BSafe  by ToolWiz
www.Toolwiz.com
About 9% of users remove it
About 1% of users remove it
About 4% of users remove it
About 6% of users remove it
 
Powered by Should I Remove It?

The file flux-setup.exe has been seen being distributed by the following 50 URLs.

http://lb.cdn.m6web.fr/d/c/a/a55b81bb30cf4c3f9f231f74db60fb37/57f994d1/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/d96a623b97d0ac96eb92b1c42aeec1c8/583608bc/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/919cec4cb88f81a4ee252e32741eb410/58046056/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/23b4731d53c21c7f7da67210e6feb7cf/57eabb6f/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/b718fc2d1017d8efd2e3f29dc6548de4/582f65cf/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/9d41df787b6e370b4b592f4617c29915/57f8ff94/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/4d7fb41e97fc9beb0552b9e5fe2ec4f6/581b8d11/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/8f34faa2f40daaa79b28126fd07a22d0/57c7292e/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/2a3d3282647fa2682c27999c758d946f/57358924/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/3ec744803bce1c8cb70b6ceb3cabf53d/565dff3d/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/a8ef94eb1a3346e460389329b2c34f5c/55fd2a9c/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/a386d896cd0c0c27f7e7f4bd786053c4/5776209d/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/05705fc78ae3148e9664592635574ab2/5810e8a1/soft/.../f-lux_3-10_fr_278130.exe

temp:flux-setup.exe

http://lb.cdn.m6web.fr/d/c/a/b7882b7554d09f326f1a48185a0ecb41/58049e57/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/d9bae6a34dfdea9e6822c3d8080379a7/568aee5e/soft/.../f-lux_3-10_fr_278130.exe

http://high.software.dn.naver.com/b93a4103592d217de85d4d55d875c4ec/.../flux-setup.exe

http://lb.cdn.m6web.fr/d/c/a/5fd65fe7b45d55c8676381d0e68e90b5/57fe8386/soft/.../f-lux_3-10_fr_278130.exe

http://download.minoc.com/2015/.../flux-setup.exe

http://lb.cdn.m6web.fr/d/c/a/2da1e83b563941a661e7ca6aed3c7e96/57f9618f/soft/.../f-lux_3-10_fr_278130.exe

http://qpdownload.com/download.php?name=f-lux

http://lb.cdn.m6web.fr/d/c/a/841a613a0f46f7a8464a2cc4e8854f27/5828f2a9/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/503b79dcb0527b865f34b0c01e86c85b/55b3e6b6/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/b47fb1b8aa616c403d44107ad6b655af/582e1ff6/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/665104542aaa0953fa1276302ad678f4/57fbbc62/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/50d4c69dbe0b6f0efb1336b448c875a9/5817fc27/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/41ccfa4476d0cab7d432b61d276dce8e/55873ae2/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/0767cbabc1a34f61fcf5ba76fe0745f3/5810ffc4/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/539c04b4d21bc844b986388e9a2d195f/57dd7520/soft/.../f-lux_3-10_fr_278130.exe

http://lb.cdn.m6web.fr/d/c/a/9e2de7af990417fb1cc9cccc70678e24/5748c80b/soft/.../f-lux_3-10_fr_278130.exe

Latest 30 of 128 download URLs

Scan flux-setup.exe - Powered by Reason Core Security