flux-setup3.exe

Michael Herf

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from update.justgetflux.com and multiple other hosts.
Publisher:
Michael Herf  (signed and verified)

MD5:
08bded58b3ef31e39e60a04432c6ec25

SHA-1:
17ba441403c8e5b94cbb6ebce24e0aafd3dd71d6

SHA-256:
230294a9da699a82a0af5115b9f73824709932f26290153495e3c03397f984ae

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:19:32 PM UTC  (today)

File size:
594.3 KB (608,568 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\flux-setup3.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/3/2012 7:00:00 PM

Valid to:
5/4/2014 6:59:59 PM

Subject:
CN=Michael Herf, O=Michael Herf, STREET=929 S. Gretna Green Way, L=Los Angeles, S=CA, PostalCode=90049, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F44D90F5015B431315399BB0349396EC

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:DhosjjbvV4PaXU5wVG95hs7Be0ApDfwTyfuL9Joe0eO9aVz2I8qCan:DhosjvVmaXUuVG9Hs1eZDfweCWveOE2g

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9511

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file flux-setup3.exe has been discovered within the following program.

F.lux  by justgetflux
Publisher's description - “f.lux fixes this: it makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day. It's even possible that you're staying up too late because of your computer. You could use f.”
stereopsis.com/flux
4% remove it
 
Powered by Should I Remove It?

The file flux-setup3.exe has been seen being distributed by the following 2 URLs.

Scan flux-setup3.exe - Powered by Reason Core Security