mp3rocket_setup.exe

Cegap

The application mp3rocket_setup.exe, “Cegap Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Cegap

Description:
Cegap Setup

MD5:
8f331d33b4b5794e84d8c63a27715cb5

SHA-1:
c36b6b6af78cb966d74568acf251f2a90d1fb899

SHA-256:
1c95305246008fca2ad792d1b03632f28dac9a72b8892243704160ef98af8365

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/5/2024 4:46:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE11 (M)
16.4.10.18

File size:
1.1 MB (1,174,749 bytes)

Product version:
4.2

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\mp3rocket_setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ft0Gti9T8s5+Wwjd+55l1It15u0qZ1wpewlPxDKB0jsO:fOGt05HIHaw1lJj

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8792

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file mp3rocket_setup.exe has been seen being distributed by the following 50 URLs.

http://www.farmsharebits.com/WVl6OTRQVWhYU0ZsYU1UUk9TVFIyZWpsS1ZtVjFkRFowWVNVeVJqTjFORkZuYld0c1RtWlZRbGxYUjB3Mk1USndOQ1V6UkNaalBWRjVhWGx1UTNwNVZVZDJXbE5YVkcxWWJETlhSVUUwVW04eFRGZzRWRlY0WVZSU2VtdHpjMWs0ZURSWFNpVXlRbW8yY201UFRUaElhWEp4T1hGUWNqSktiRzE1V1V0WVZuRklNWEkzVkdGM2R6Z3dhRlJTYld3d2FucEhPWFpLY0VOR01ISklRelZzTkRWbmJUaHNlV2czT1ZOT2FYQmhkREpuZUZKeVpEUnhKVEpHVVNaa2IzZHViRzloWkVGelBVMVFNMUp2WTJ0bGRGOVRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWjNkM2N1YVcxMWMybGpjMlZoY21Ob0xtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtMXdNM0p2WTJ0bGRDNWxlR1U9

http://www.farmsharebits.com/c?x=auLxZoZA1 dVLdN7v6gBNXPrpyV3etwoMjIsmUe2p78=&c=/x1Sh/EsCZqtYkvzv/T04gxeqNxjbyn1XkAKcO PwVj3auSmZ2SlKwf4ZRtO1upyCUG/bNf9Sif/PGS4WUSEnYvBoESGQFyEHvxfpXhDc7fdRXJPuCgkAxjKaGQvGgh2WvJqJPAbLbTzUfLtVTU5qhhGoWE0K2diCJulTzZ8Sx4K6TqSHg/9ehwtKtW3PMRV&e=1&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.safefiles.com/.../mp3rocket.exe

http://www.farmsharebits.com/WVl6OTRQVlpyUmxObk1FNVhTRWhsUm5WUU1IaFBXVEU1VFdoS00xVXlSMFJMWW5SdGRDVXlRa3h2YUhsbVYxQmFkeVV6UkNaalBXODNKVEpDZGxSaWNuSm1NV1p2YlRjeGVteE9VRlE0ZUVwR1VHWlpaeVV5UmtwVU1tTTJSVUp2Y1had01IbEVkV0pFV21vM1NVUnVKVEpDU1c5VlpEZHlOM2hYVlVsTE0zRkNaM1ZWYUZsNlpYaEJWMUV3TjJoWVREZDBiMGd6V0haR05rSmxOMnByWVRKMVFscDVUMUZCYWpsMWFYZG9KVEpDZGlVeVFrOXJVV2RwUWpaRGVWSXpla3c1ZGtRelduUm9NSGhQTjAxbFprSlVUMW8xVEVFbE0wUWxNMFFtWlQweEptUnZkMjVzYjJGa1FYTTlUVkF6VW05amEyVjBYMU5sZEhWd0xtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbmQzZHk1ellXWmxabWxzWlhNdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JYQXpjbTlqYTJWMExtVjRaUT09

http://www.farmsharebits.com/WVl6OTRQWEJwZVc5RVNYZGpWR1lsTWtaME9VbFJlRUo1SlRKR1RGWklTMkpNU2pWU1UyOXlTVXhQVEhKQ1JteGpNbWc0SlRORUptTTlKVEpHVFZwelpEUktiQ1V5UmxkRU5GRkZUWEpIWmxaNGN6aFNKVEpDY0doc2QyWlVKVEpHVkRVNVpHOUxaSFUyUm1SR1NHVndiRk5wWTNSdVdFdGxUVzVWYW1oS1FTVXlSakY2U2t0VFoxcGhPR2RHYVRsb1ZUQnZRamNsTWtKbFZUaDFXV1owVWprNFZUTmpha2xQSlRKQ1VsZFhTbWR1UlV0dGEwRWxNa1p1YVZWYVlUa2xNa0pqTVVGT1JXWkpNVFVtWkc5M2JteHZZV1JCY3oxTlVETlNiMk5yWlhSZlUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbk5oWm1WbWFXeGxjeTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p0Y0ROeWIyTnJaWFF1WlhobA==

http://www.farmsharebits.com/WVl6OTRQVkJqWTJWME5Fb3phbEpGWTFKRlQwUjBSMDl0VEV4R05EZHZRbGhpYkVOdk1VMUZaREZJWTJremJsRWxNMFFtWXoxclZuVXhNVU5ZTTNkSlRISkhjSE5PYkRodlNEVjNkelpRTkRocmVIZFhUSEphZVdwQmNUaFROMjg0TjJGMFRXdHdNM3BDSlRKR1ZWQmtiVUYwYmpSSlUwVlJjRmxSYzNwM1NHZHlPRWRQYlhNbE1rSnBKVEpDZURKTmVITk1VMHM1YkVOdlNWVTRlWEZCUm1RelkxVldkMkZZZFRoUlpsSlBWbWhRTVdnMVV6WkZRV1o1Y0Naa2IzZHViRzloWkVGelBVMVFNMUp2WTJ0bGRGOVRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWjNkM2N1YzJGbVpXWnBiR1Z6TG1OdmJTVXlSbVJ2ZDI1c2IyRmtjeVV5Um0xd00zSnZZMnRsZEM1bGVHVT0=

http://www.farmsharebits.com/WVl6OTRQWEJ5SlRKQ1NGTlVkbFp3WlU1dldYVjFTM1o2SlRKQ1oxRkdRU1V5Um1sdWRVTnlSRFpLTnpkTlFpVXlRa1EwTnpsdVRTVXpSQ1pqUFRoc1NVUTNWMWRzY1dwRk5rd2xNa1p1YzA1eFpHRXdjV1ZLTVdjNGRHaE5XVTFvY0VFd0pUSkdNbXh5TW1SRFNUWnBXa05JVkdOQlRHcFFVRlJoZVhGWGFUQnZhVGt5VURWelQyMTRlV2xHTWtoTVdDVXlSbGswV0VOcmQwRnNTbTl4TXpsSVpWaDFhbFl6T0dGa1drNU5OelZSU3pCMUpUSkNiR0k0TWtoSWNYbEVjMHhLUVhvbVpHOTNibXh2WVdSQmN6MU5VRE5TYjJOclpYUmZVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG5OaFptVm1hV3hsY3k1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadGNETnliMk5yWlhRdVpYaGw=

http://www.farmsharebits.com/WVl6OTRQWHB5ZG1nMFIyMVlVVzFRTmtaSU9EWkdZVkptYkVWbFMyVkRiMjkxVVRKb2NXcDNjMDlvY2pSdFJHY2xNMFFtWXoxeVVYTXlUa1ZaVkRGYVNqbGtjakE0YkZWRFQxZFhjbWgzU1RjMFdVbGxURmR3VGs5dlEwOTFVV3RtZUhwalRWRlBWWGswTTNkaFpISmlkamswVEdseFlUaFpWRE5zYWpKQ1lVaFFTV3BtTlRORVFscHNWWGRYVjJoclVETnZORzVMVlhSWU9GRXhibk5tTlVST2REQlpXbXBhTjNwdVZIazRWV2hTTjBSWmVpWmtiM2R1Ykc5aFpFRnpQVTFRTTFKdlkydGxkRjlUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdWMyRm1aV1pwYkdWekxtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtMXdNM0p2WTJ0bGRDNWxlR1U9

http://www.farmsharebits.com/WVl6OTRQVXhRUWtONU1VcDFORk5yWTBJNWFFSjFOVVY1V2xCTWVqWnFlWEZxVUdObWR5VXlSbFpRT0c1TU1GTXlaeVV6UkNaalBUaFZXbFJOZWxGTmNtNDFZMHN3YUZGUVIwVnlKVEpHU205MGNXNUVjVGRLU21ocGVHOTBUWEpGYWpKTlJuUWxNa1k0ZUZKS2JYTlpkelZ0VWlVeVFqSkdSVFEwVkZGVWJEVktUeVV5UmtVMFoxUkxTREJUU1ZsVVRIVjZVbGhqU25ob1kxUkNaSE0xWW0xclRXRTBaRTluYUV4UWVuSm5jbXRLUkZvM1YyVWxNa1p3VkZrbE1rWnZSRUpHSm1SdmQyNXNiMkZrUVhNOVRWQXpVbTlqYTJWMFgxTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTV6WVdabFptbHNaWE11WTI5dEpUSkdaRzkzYm14dllXUnpKVEpHYlhBemNtOWphMlYwTG1WNFpRPT0=

http://www.farmsharebits.com/c?x=AxndEpc5UFBuVxdCiXfQsI ChnepVXMzJ ZYlnQaq0A=&c=ziQku8rG9fuWWmd6UGmMIgEGRNFLCEWK k7U00Xknq1rxTp/N byU41IK7udPTjx8Kl5dbBXZggxK gp9PDNWlAI1hqVaWvMf1eU2Sds0q46cuYte9WYC5zFL1T3gJWPdXAxxdudktYBXvJGjSUdK3KTrV3aSOoLYgRO1awkIrUbVKDUrfNpob0Iv3zlu4gy&e=1&downloadAs=MP3Rocket_Setup.exe&fallback_url=http://www.safefiles.com/.../mp3rocket.exe

Latest 30 of 87 download URLs

Remove mp3rocket_setup.exe - Powered by Reason Core Security