flux-setup.exe

Michael Herf

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from d38qbqfndhlqd2.cloudfront.net and multiple other hosts.
Publisher:
Michael Herf  (signed and verified)

MD5:
ad2ef8cab44c1cf813260a5e65246df9

SHA-1:
bcfdf981eb5bb43c9acb831263eb786223ebd65b

SHA-256:
e99966edc92d8fbd8f73c778a35c347b2e2cceef0177684f343eebc951bf6114

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 12:36:19 AM UTC  (today)

File size:
583.2 KB (597,224 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flux-setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/3/2012 8:00:00 PM

Valid to:
5/4/2014 7:59:59 PM

Subject:
CN=Michael Herf, O=Michael Herf, STREET=929 S. Gretna Green Way, L=Los Angeles, S=CA, PostalCode=90049, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F44D90F5015B431315399BB0349396EC

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:l2aD6/ZSMcTTlNvEKVtdW1nSA/gTyte0eO9aVz2I8qCgw:l2aD6xSMYNpVTWsA/getveOE2I8qCgw

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9494

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file flux-setup.exe has been discovered within the following program.

F.lux  by justgetflux
Publisher's description - “f.lux fixes this: it makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day. It's even possible that you're staying up too late because of your computer. You could use f.”
stereopsis.com/flux
4% remove it
 
Powered by Should I Remove It?

The file flux-setup.exe has been seen being distributed by the following 9 URLs.

https://d38qbqfndhlqd2.cloudfront.net/flux-setup3-9.exe

http://www.toucharger.com/.../2101284e.dl

&onid=2094&oid=3001-2094_4-75447318&rsid=cbsidownloadcomsite&sl=en&sc=us&pdguid=download:13393777&topicguid=utilities/sys&topicbrcrm=windows software&pid=13393777&mfgid=10145824&merid=10145824&ctype=dm&cval=NONE&devicetype=desktop&pguid=8e32eb3faaf8b472cda06f8c&viewguid=QbeAzEp-qpmdQ7y3w5EmB@dRFm2G2m7dStMx&destUrl=http://software-files-a.cnet.com/s/software/13/39/37/.../flux-setup.exe

Scan flux-setup.exe - Powered by Reason Core Security