psafesetup_v1.0.1.1935.exe

PSafe Tecnologia S.A.

The application psafesetup_v1.0.1.1935.exe by PSafe Tecnologia S.A has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a setup program which is used to install the application. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from setup.psafe.com.
Publisher:
PSafe Tecnologia S.A.  (signed and verified)

MD5:
57cf728db9116979c691760f3cdb9207

SHA-1:
11bc9f5bf84dd09629b6fd1362ef208ae1ec52e6

SHA-256:
8f316005b7b461ac9ba990ac42a040cf93b2b80517aa5c9b2860bff18a0114c7

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 9:25:34 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.Gen
8.3.2.4

Dr.Web
Adware.InstallCore.53
9.0.1.0173

ESET NOD32
Win32/InstallCore.AE potentially unwanted (variant)
10.12883

F-Prot
W32/InstallCore.V2.gen
v6.4.7.1.166

Reason Heuristics
PUP.InstallCore.ENG (M)
16.6.21.12

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16619

SUPERAntiSpyware
9068

File size:
1.1 MB (1,186,056 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\psafesetup_v1.0.1.1935.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
3/27/2011 9:00:00 PM

Valid to:
4/1/2013 9:00:00 AM

Subject:
CN=PSafe Tecnologia S.A., O=PSafe Tecnologia S.A., L=Rio de Janeiro, S=Rio de Janeiro, C=BR

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06F54713CAC751068B23F9C036259F2F

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Xg9Y07TaybmYnZdNOF+o7R6TcaZffzjE1/Lq2fZPeTm:wqiNbmYnDNXoATc8I1hPeS

Entry address:
0xC96B0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 50, 1A, 40, 00, E8, 3F, DD, FF, FF, 7F, 16, 8B, 15, 1C, 76, 46, 00, 8B, 54, 82, F4, 85, D2, 75, 08, 40, 3D, 01, 04, 00, 00, 75, EA, 8B, C2, C3, 53, 56, 57, 55, 8B, F0, BF, 10, 76, 46, 00, BD, 14, 76, 46, 00, 8B, 1D, 08, 76, 46, 00, 3B, 73, 08, 0F, 8E, 84, 00, 00, 00, 8B, 1F, 8B, 43, 08, 3B, F0, 7E, 7B, 89, 73, 08, 8B, 5B, 04, 3B, 73, 08, 7F, F8, 8B, 17, 89, 42, 08, 3B, 1F, 74, 04, 89, 1F, EB, 63, 81, FE, 00, 10, 00, 00, 7F, 0D, 8B, C6, E8, 85, FF, FF, FF, 8B, D8, 85, DB, 75, 4E...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
818 KB (837,632 bytes)

The file psafesetup_v1.0.1.1935.exe has been seen being distributed by the following URL.

Remove psafesetup_v1.0.1.1935.exe - Powered by Reason Core Security