junipersetupclientinstaller.exe

Juniper Setup Client

Juniper Networks, Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with Junos Pulse. The file has been seen being downloaded from vpn.lshauto.cn and multiple other hosts.
Publisher:
Juniper Networks, Inc.  (signed and verified)

Product:
Juniper Setup Client

Description:
Juniper Setup Client Installer

Version:
7.4.2.34169

MD5:
c392ecc9b6bfe86e4459a42b5f47958f

SHA-1:
84cfe59ca77d5c28a4b507f94a1579b86db01e19

SHA-256:
3fbda71ebe5417e891d8e7c6980273f5efc68326747ea0b2d167a69525116957

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 7:35:41 AM UTC  (today)

File size:
1.7 MB (1,810,496 bytes)

Copyright:
Copyright © 2001-2013 Juniper Networks, Inc. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 5:00:00 PM

Valid to:
4/10/2015 4:59:59 PM

Subject:
CN="Juniper Networks, Inc.", OU=ASG-Engineering 2012, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Juniper Networks, Inc.", L=Sunnyvale, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E9224BB3CAF2A41F1E0F796379EE23F

File PE Metadata
Compilation timestamp:
9/4/2009 3:07:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:HF8vNu2yAahVcRbrCoGB3ppcUeeuK7Xah:HF/28hVwspVeeb7Kh

Entry address:
0x361B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 48, 8A, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 80, 40, 00, 53, FF, 15, 8C, 82, 40, 00, 6A, 08, A3, D8, 58, 42, 00, E8, DB, 27, 00, 00, 53, 68, 60, 01, 00, 00, A3, E0, 57, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 8A, 40, 00, FF, 15, 5C, 81, 40, 00, 68, 38, 8A, 40, 00, 68, E0, 4F, 42, 00, E8, D0, 24, 00, 00, FF, 15, AC, 80, 40, 00, 50, BF, 00, B0, 42, 00, 57, E8, BE, 24, 00, 00...
 
[+]

Entropy:
7.9965

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file junipersetupclientinstaller.exe has been discovered within the following program.

Junos Pulse  by Juniper Networks, Inc.
Publisher's description - “Junos Pulse is an endpoint software platform that enables dynamic SSL VPN connectivity, network access control (NAC), mobile security, online meetings and collaboration, and application acceleration, through a simple yet elegant user interface.”
www.juniper.net
8% remove it
 
Powered by Should I Remove It?

The file junipersetupclientinstaller.exe has been seen being distributed by the following 8 URLs.

https://vpn.lshauto.cn/dana-cached/.../JuniperSetupClientInstaller.exe

https://vpn.emal.ae/dana-cached/.../JuniperSetupClientInstaller.exe

https://ra.thy.com/dana-cached/.../JuniperSetupClientInstaller.exe

Scan junipersetupclientinstaller.exe - Powered by Reason Core Security