internet explorer setup.exe

The application internet explorer setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from vpn.mcleodhealth.org.
MD5:
fc4129fc092017faa374997659ee4cfa

SHA-1:
62f13775518094dbc191e64f7b5b012b4d1df1c0

SHA-256:
d85718ea4c75320deaf4e8fa1f8caaf80125cf28e405025228f607e593509431

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/27/2024 9:03:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.3.8.19

File size:
2.6 KB (2,622 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\internet explorer setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
48:3qy5/O4+bu0ogxEr+oiHqhp7DeLzzJX8HD8d4hImnAHoExNmCvhW:3zc4tmdMHDN4HDNlW

Entry point:
0D, 0A, 0D, 0A, 3C, 21, 44, 4F, 43, 54, 59, 50, 45, 20, 48, 54, 4D, 4C, 20, 50, 55, 42, 4C, 49, 43, 20, 22, 2D, 2F, 2F, 57, 33, 43, 2F, 2F, 44, 54, 44, 20, 48, 54, 4D, 4C, 20, 34, 2E, 30, 31, 20, 54, 72, 61, 6E, 73, 69, 74, 69, 6F, 6E, 61, 6C, 2F, 2F, 45, 4E, 22, 20, 22, 68, 74, 74, 70, 3A, 2F, 2F, 77, 77, 77, 2E, 77, 33, 2E, 6F, 72, 67, 2F, 54, 52, 2F, 68, 74, 6D, 6C, 34, 2F, 6C, 6F, 6F, 73, 65, 2E, 64, 74, 64, 22, 3E, 0D, 0A, 3C, 68, 74, 6D, 6C, 3E, 0D, 0A, 3C, 68, 65, 61, 64, 3E, 0D, 0A, 20, 20, 20, 20...
 
[+]

Entropy:
5.2928

The file internet explorer setup.exe has been seen being distributed by the following URL.

Remove internet explorer setup.exe - Powered by Reason Core Security