freefileviewersetup.exe

Sak

Locat

The application freefileviewersetup.exe, “Sak Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Locat

Product:
Sak

Description:
Sak Setup

MD5:
c0eb9a2398d6f33a69c394517268bd74

SHA-1:
eb0dbbb899181fcb158c75acb04dc31e8a32492b

SHA-256:
a335134b2c733fcc1e5b68573f4d174cf1a1fc7fe6a291d1a411e154db13fd19

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 3:47:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.11 (M)
16.3.6.9

File size:
1.1 MB (1,164,316 bytes)

Product version:
3.2.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\freefileviewersetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:bCzSuQK2mOouEq50eNKMp7hkats2COTy7WlhJ0FzGjdD5wc8oyQTd4XT4j1jl0w2:bCzMK2mOo0TgAkaS2vnl7Sz0dFwrb843

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8696

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file freefileviewersetup.exe has been seen being distributed by the following 50 URLs.

http://www.bulkfactoryranch.com/c?x=LUbLt4hxg0luEbNAjEeS9E6IGXXfSHm5sF2IPgczyNQ=&c=4W4471BACxP6SvdrZpVZRFZn9duMmKornyhbqnvfrDZpfXC2ujenLg4x7ZLbF8fpAaE 3vFhJQe8M/kQVqN JxRwjn6gXFp/RObW6VF108QSJ/asTTrAea82kJ32x5QDInLQSGf6LYnbxbYZr2WChYoSo8sOxGPjapDzv415ApWmo/Mp89GtQAEkFLz4WDN &e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.conceptsbitsvaults.com/c?x=sq06dGmvQ5dLRDFZbiuRsf0fWmhfnuSMWXWWCm irNI=&c=WDxg5/TQd8RjYLpkaFqTnfNFaakg5B6xxXPudy1rqvbxUM930UgoFHrMfQJaPOPcxaWM3qitgkax2FRLCtyFTOlJHF4RPt/Hp73hM/izI1kL3OHq8KcDPC3yr11bn74qKfTLW53oURX/wAAmat93YP6mIX/9Yk6wd8N45gJrTaXiJmFCh/d3JfO98qOguZu5&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.towersoftwarebundle.com/c?x=dwb/nSpGsPZnabOjf69KBEomdxS1ra/k9sRdjxbq2U8=&c=0bek38ax3U3pWXX1wsgQlJJwXLr7yyJqKrXj9q7quNC4WSkvKTX2duEfQSk82CPpkXrXe19oYMisfcLZGYY3pJpNVAjtF9G8ehKA/WvdomqRE9RU gwNfLzL5lkouLxd9uWp96bcY6QmkJxxUe PDdUI7BG0ZlBsB17W/Md8E9NuMY7/OHaFF91iSt0Jrbu &e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.applicationsharestock.com/c?x=EJQeaNaqQOSfXo1 t9zRWHEW4wu8nbGFtKAD8QThCTk=&c=bTwnWW5vh5y96hyaccunauxmd/9eG3I6dXDN2/jRryHlVBWHQD1WTylIdNxKz0WlD5GQLA7qC1riGRbF3cwuPhftfLGEYkJpKQ8kG4QJU86OdmOXzcpzPeOWvRsCN8JdCDLAtv9dcEJdXCx7oIPrKy0EEv2Q QaJLK/e7oR5UayXXIL9wyQq iVUcYda8zd7&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.presentfilestag.com/WVl6OTRQV2R4WlhSMlZpVXlSaVV5Um1wb1pHdDZWSEYyWkRoaGQweHVTRkJJYzFoMWNqSnZja2RoUTNObGNXSTRPREU0SlRORUptTTlUWGRyYzNwNVFVZHBXVkZ3ZVZsTldFVklZVmROU1dwVmMxTjJXbVp3VnpObE5UVjJORUZaWkZKWFducFZkMkpLWlZkSlkxWmxkRkpWUzNaTU5HbzRWbmxoVW5VeVVITkdSbkZRTld4WVVEQnBjbVJhSlRKQ1NsQlRlV0pYYkdoc1kzQTVVbUowYVRaVU5FcDZUM1I2YUhsU1ZIbFFVMEUyYXpOQ1dYUkZUelZSWlNaa2IzZHViRzloWkVGelBVWnlaV1ZHYVd4bFZtbGxkMlZ5VTJWMGRYQXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xtWnlaV1ZtYVd4bGRtbGxkMlZ5TG1OdmJTVXlSbVJ2ZDI1c2IyRmtjeVV5Um01bGQyVnpkQzVsZUdVPQ==

http://www.clearpackagedownload.com/c?x=G6v2HYbveH lZpDJAy31fjU9Eu7EukH/wV08RxNWB2g=&c=6j eZPC2eAA6RN9Ak9HRgSCNgR43nsVuyxYBcgeCpilLWqar/crsLL0A5nldx7HzA6PYI32KHgMq4N9g5PGkEVwqJfqq1Iit73fM0du5CDyYoYze6zabe6Zjsxzia KVINWoSS0 SPFCQ4zwIv2Dq1sG1PUu8/j59YNRE fwR7KbsUraDWaCVb9dqoWqUm A&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.binariesupdatehead.com/c?x=j9ynuvLPHZ6oTXPbBBZOz6qA2aLQ9ypDNSy9hrdY2Lg=&c=wGoSV71cRIWWTEJsdDg25XEO92oP/WqDI2xp89EmM56waSLk7LBX/Fb6meoSbHkPnUr8N6GWC1aDb2d14uMBWlWR/ETkS7tXuCz5vNq Xj2vmT6adTXnDu6c//cDnySE5kGTCb6AauA0LjJcX s24CnRKftqq ayqqTtPMqdoBNUPabcVU0e65WJ 8mjEj1&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.farmranchcentral.com/WVl6OTRQVEJaVVZrNVYzUnNRVlZ3UjNKS2FtOVRPVFEyVm5VemFFYzRTVFZuZDBSWWVtdHlTRkpvYzFOVE5IY2xNMFFtWXoxUmNrbFRXa3BJVDFGdFQwRkdNSEZTUlRGcFlVVllWblpSSlRKR2FWWnFWMWxuWlU4eGVuSmlkRzFYYkRWUE1GRm9NVzR3UkdsSGJGWjBNRk5zVEVOTWJHMTJVRGRKTUhKMFFWRnhTSFJtTlhSdVF6ZGFTamMwVkRnMk1HbEpNVWwwZWpGQlYxUnljaVV5UWxSTlowcFVSbWhLWkhGc2NXSmlKVEpHY0U4M1psUkNiV3hJSlRKQ1NIZFdRemQ1TmpWRFNXcGxXVGhLT1dJMVFVNVlVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxR2NtVmxSbWxzWlZacFpYZGxjbE5sZEhWd0xtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbmQzZHk1bWNtVmxabWxzWlhacFpYZGxjaTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p1WlhkbGMzUXVaWGhs

http://www.conecptbundlescity.com/c?x=oOVMDGif97p3SknvfnzPQdEUjAgqtd5A2iW6URSIR/g=&c=IxGqp43G9bvHXi01rDERomR4A/WCm6JSC6bGNyYXYTGZ9vvEL dB3dyz2eR228xnxDsOD9nUknMjD9x1PR J8mo3zOUf0kUZgiETTDo/QKMO2HnLFhGsoQliZIIWakBflFFSs86mQiT qFgyRBFC1XFnI6ZE9P0VoGPqildcu2X6H5razHsCPtMTOCeepM6b&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.bodysignsheart.com/WVl6OTRQVWM1UTBwbFNsbGlaRFJoUlcwellWbG5UMHhNVjJ4SFozWjVkM2h2Y2tONVNFaENkR1pwYUV4NVpFMGxNMFFtWXowNWRYSTNZalpETUZWMmFYbEhRbXBpV210S05VVXhUMHg2T1VKVlJVWkdVSE5OWkVsc0pUSkNaMkZvYkZaeFEzUmtkRkpFUmt0Qk5XZ2xNa0pSWTIxdFYxSTRUM1pMVUdKVWRWZEZOa2xaV1RWS0pUSkNlSEJhSlRKR2JVMVhKVEpHTTBaWWFrZHlNVm94WkVaUkpUSkdaVzVQUTJSd05tSnBSM0pKVG5GRVV6UmxWVVo0VERKS09WQjBjbXBHTlV3elJXTk5OMU0xSlRKQ1ozWTBVVzVGTVdwb1VTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFHY21WbFJtbHNaVlpwWlhkbGNsTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVtY21WbFptbHNaWFpwWlhkbGNpNWpiMjBsTWtaa2IzZHViRzloWkhNbE1rWnVaWGRsYzNRdVpYaGw=

http://www.vaultappsranch.com/c?x=vequqCOnNcTEuv9eiH/Bi60nSOCEcp4EwWGsroZk4tA=&c=RNyGyL 1Oxc3PWntk2QmycExKaEc 8WRzQzr0tNfvfL69HAYQuTfEi X76QWU9PGKHehu0X1VdkTgt2YbOO2sXnXSXUckt7mqOwxUkQDBYE2GZ5Skih1dGk1aoDB3QCnL5JISypzZd9/tnPpQ2GUrP9PpmH5pG8/viskvhPZ9bcAgSzSx9i5ijppLSFzNSNn&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.binariesupdatehead.com/WVl6OTRQVEp0ZWtGclJsbHdWak5wTWxodldWUTBUVVZJVERCVGFrOVhOazFLUWxwQk1GTjZOV3hzVWpSaFQxRWxNMFFtWXoweGVERnlla0p4VFRGSGFpVXlSbE5rUldGcFIzbE1OV0pNWm5GVU9WUTFNbTVKUTNCek5GWkNVVUZtU2twUFdsTnlTMkpSVm10cGRqVTVKVEpDTjJaVWRVeEpPRGRwVlV4RU4xWnJjbE41VTAxS2REZFFTa2xJTUVScGJGUkJTVTFOV0ZsVlJVZFlNakpsSlRKR1dYb3dVMlFsTWtJNU5sUlpZMHBKZVcweVRsUjZKVEpHUkhoeE5UaEhjRWR0UTNGSVJXdzNVME5JUXlVeVFsRlpORmMxVFVFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlSbkpsWlVacGJHVldhV1YzWlhKVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VabkpsWldacGJHVjJhV1YzWlhJdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.binariesfarmsend.com/c?x=0WPwcPDRhzje8gD29mGp acenk0VYJ411jp qJAtexs=&c=rRl6mPrRoOS/ L48wHVsRrwumPMDDp5KRgXVzC7e9AW0om2cdWCGCP2ri3aqL8JFRXOi17AKJBM3qN57NDM ON0dh7VnAlbemeYCsbc9gPxDodVs9fxz010zmj5p200VoL0kMSEyPINCeO9pLG4VE7yb8V5X9HUaBgZa7WK0YXR/NiyOTtJHzMMAIkFs8kCE&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

Latest 30 of 186 download URLs

Remove freefileviewersetup.exe - Powered by Reason Core Security