java_setup.exe

The executable java_setup.exe has been detected as malware by 2 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from bit.ly and multiple other hosts.
MD5:
4d70b024d7389ea2d713f7fdec5240cf

SHA-1:
ca2db323e3bd4cadc1a8da73321662fba6bbb73e

SHA-256:
9a544a14bb793f83974de1e9218717d1cc7fa62ec8bdd01ef96e83d35d97df37

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
12/25/2024 4:59:49 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160326-0

ESET NOD32
Win32/TrojanDownloader.Banload.XDR trojan
8.0.319.0

File size:
2.2 MB (2,258,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\java_setup.exe

File PE Metadata
Compilation timestamp:
4/28/2016 4:28:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:7KoSdvj5/l5YPgpyKXhKIEQyTprS8QNM:7GNl6PsYsiriS

Entry address:
0x1DA698

Entry point:
55, 8B, EC, 83, C4, F0, B8, 38, 07, 5D, 00, E8, 44, 09, E3, FF, 68, 10, A7, 5D, 00, 6A, 00, 6A, 00, E8, 32, 1B, E3, FF, E8, 85, 1C, E3, FF, 3D, B7, 00, 00, 00, 75, 0C, A1, FC, 71, 5E, 00, 8B, 00, E8, 26, 5B, EE, FF, A1, FC, 71, 5E, 00, 8B, 00, E8, 92, 58, EE, FF, 8B, 0D, D0, 6B, 5E, 00, A1, FC, 71, 5E, 00, 8B, 00, 8B, 15, 80, F9, 5C, 00, E8, 92, 58, EE, FF, A1, FC, 71, 5E, 00, 8B, 00, C6, 40, 5B, 00, A1, FC, 71, 5E, 00, 8B, 00, E8, CB, 59, EE, FF, E8, 2E, BB, E2, FF, 00, 00, 4F, 00, 58, 00, 30, 00, 34, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.8 MB (1,939,456 bytes)

The file java_setup.exe has been seen being distributed by the following 2 URLs.

http://bit.ly/1SsLU6r

Remove java_setup.exe - Powered by Reason Core Security