prsetup.exe

Allied Way International Holdings Limited

This is a self-extracting archive and installer. The file has been seen being downloaded from proxyrental.net.
Publisher:

MD5:
4d6e96238e7bc9cee376c65dbd93b949

SHA-1:
ed25d052076ded82a76930fd2fb18fc4fb8c54f1

SHA-256:
63e8626263314ce73989d20ac36f842b582e88a13a94afa4b4df2eb771ba4c4d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 11:21:01 PM UTC  (a few moments ago)

File size:
2.4 MB (2,464,376 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\prsetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/5/2015 12:08:43 AM

Valid to:
12/18/2018 12:49:39 AM

Subject:
E=support@proxyrental.net, CN=Allied Way International Holdings Limited, O=Allied Way International Holdings Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D7C165529E9CC587A70ACBCFA7E8775F

File PE Metadata
Compilation timestamp:
8/14/2016 12:15:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0xFCE7

Entry point:
E8, 09, 05, 00, 00, E9, 80, FE, FF, FF, 3B, 0D, A8, B0, 42, 00, F2, 75, 02, F2, C3, F2, E9, 7E, 06, 00, 00, E9, 89, 4C, 00, 00, 55, 8B, EC, 83, 25, 60, 79, 45, 00, 00, 83, EC, 2C, 53, 33, DB, 43, 09, 1D, AC, B0, 42, 00, 6A, 0A, E8, BD, 1B, 01, 00, 85, C0, 0F, 84, 74, 01, 00, 00, 83, 65, EC, 00, 33, C0, 83, 0D, AC, B0, 42, 00, 02, 33, C9, 56, 57, 89, 1D, 60, 79, 45, 00, 8D, 7D, D4, 53, 0F, A2, 8B, F3, 5B, 89, 07, 89, 77, 04, 89, 4F, 08, 89, 57, 0C, 8B, 45, D4, 8B, 4D, E0, 89, 45, F4, 81, F1, 69, 6E, 65, 49...
 
[+]

Entropy:
7.9652  (probably packed)

Code size:
132 KB (135,168 bytes)

The file prsetup.exe has been seen being distributed by the following URL.

http://proxyrental.net/download.ashx?key=b5bsm ueARBnv9 bgVi KPc7nqD5HJOQb5cUsEwN I1cE2VgWnCDW0Vw5o5Oo0gNlwc7c9c8ljE9KN7rcx0voCtGTQLAryutolY1ADPRC4snb6uUFVu56IlkzFkcV15C

Scan prsetup.exe - Powered by Reason Core Security