free450setup.exe

FREE450

G R Freeth

The application free450setup.exe, “FREE450 installer ” by G R Freeth has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.g4hfq.co.uk.
Publisher:
G R Freeth, G4HFQ   (signed by G R Freeth)

Product:
FREE450

Description:
FREE450 installer

MD5:
11c1daf2e3aa2237413b682163cb427a

SHA-1:
4e4047e08c5fa8f2c5b98dd5855659389e41918b

SHA-256:
3c8540756206f91d665df81aec0836b576f6032e1312e1f0f747dcfefe8696fb

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/25/2024 6:42:04 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.12.17

File size:
1.5 MB (1,531,120 bytes)

Copyright:
Copyright 2016 © G R Freeth

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\free450setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/17/2016 4:00:00 PM

Valid to:
1/17/2018 3:59:59 PM

Subject:
CN=G R Freeth, O=G R Freeth, STREET=9 South Avenue, L=New Milton, S=Hampshire, PostalCode=BH25 6EY, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7519E4C554A04B08A3571942EC79871E

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:zQiMKVDtFiZoTp2ULzVy7gXtxdoESjtUlqAXlVFE/Nia/z3oFEdH7McG6E3o1Tvl:z9BDXiZoTp2mZyIGelVVVMiYVH7ML6E7

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9903

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file free450setup.exe has been seen being distributed by the following URL.

http://www.g4hfq.co.uk/.../FREE450Setup.exe

Remove free450setup.exe - Powered by Reason Core Security