nsissetup.exe

Free-mium GmbH

The application nsissetup.exe by Free-mium GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. While running, it connects to the Internet address live.xm2.swv-server.de on port 80 using the HTTP protocol.
Publisher:
Free-mium GmbH  (signed and verified)

MD5:
793cd0a9f4e14d43f7cda94e98517886

SHA-1:
c2b25d75e65825b19dd1013858f52e3aaa8cf899

SHA-256:
3d65e0f3b4dbb8cbe994b2fa7b1031a8346f0129fb530ad50fe6a7fddfcb0238

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 5:11:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Freemium.Installer (M)
16.2.5.16

File size:
547.5 KB (560,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\nsissetup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/29/2015 2:00:00 AM

Valid to:
4/29/2016 1:59:59 AM

Subject:
CN=Free-mium GmbH, O=Free-mium GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3AF8BC0C86618D48C79383622867AB5F

File PE Metadata
Compilation timestamp:
2/2/2016 1:18:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:KDQDYycyTYVnxYXSyLymzXKNyy1yI1vrqmOJtgtt8ER:8Vy0VxYX5EbUuvrqHJStt8ER

Entry address:
0x2161C

Entry point:
E8, 74, 7B, 00, 00, E9, 89, FE, FF, FF, B8, DA, 9C, 42, 00, A3, 60, 73, 46, 00, C7, 05, 64, 73, 46, 00, D0, 93, 42, 00, C7, 05, 68, 73, 46, 00, 84, 93, 42, 00, C7, 05, 6C, 73, 46, 00, BD, 93, 42, 00, C7, 05, 70, 73, 46, 00, 26, 93, 42, 00, A3, 74, 73, 46, 00, C7, 05, 78, 73, 46, 00, 52, 9C, 42, 00, C7, 05, 7C, 73, 46, 00, 42, 93, 42, 00, C7, 05, 80, 73, 46, 00, A4, 92, 42, 00, C7, 05, 84, 73, 46, 00, 30, 92, 42, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, 85, 86, 00, 00, DB...
 
[+]

Code size:
347 KB (355,328 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to live.xm2.swv-server.de  (148.251.236.185:80)

Remove nsissetup.exe - Powered by Reason Core Security