isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from dl.yac.mx and multiple other hosts.
MD5:
2948122fcf8c8e902cb3eb06327e2718

SHA-1:
3e6fcd0a9710732bb3e35aa5076edf0252222743

SHA-256:
fb948b9b7d71a18f8f4de4e929ad3b717c9ee556ede77d39094f5a754cd6704b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:35:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.YAC (M)
16.6.17.18

File size:
13.6 MB (14,243,152 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:orruWmo+AxRebD2EPbbQRUG1WZa9Re/GIa:ouA6hOUTZa9Re/Q

Entry point:
3F, CB, 11, 42, 9D, 24, 31, 4F, 5B, 1B, 00, BD, E9, D7, F4, BD, 00, 10, 40, F0, 6C, 5F, 38, 10, AE, 33, A5, D2, 08, 45, 57, 39, 43, 1A, E0, A3, D3, 97, 84, E3, E2, 50, DC, B6, BA, E3, F8, 3E, 13, B9, 56, 0F, 46, 19, 61, 24, D2, A2, B2, 13, F9, BF, BB, F9, F1, 0D, 6E, 65, 51, EE, A3, 84, D3, C1, 8E, 4B, 63, 55, 80, 31, 34, 20, 23, C0, 14, 49, 9B, 08, F4, BF, 51, AA, FA, EE, B5, C8, 1A, 68, 83, C5, 98, 58, CE, 0E, 50, B0, C5, C1, C9, EA, 79, 4E, E7, D7, 52, 2E, 35, C7, A5, B7, 9A, AF, DB, 8A, B1, 7F, 75, 49...
 
[+]

The file isafe_setup.exe has been seen being distributed by the following 2 URLs.

Remove isafe_setup.exe - Powered by Reason Core Security