raft_setup.exe

Fulese

Morava Group

The application raft_setup.exe, “Fulese Setup ” by Morava Group has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.downloadtourapplication.com.
Publisher:
Morava Group  (signed and verified)

Product:
Fulese

Description:
Fulese Setup

Version:
3.2.4.4

MD5:
ceb8b0c5519e3bf5da0cfbf87de95151

SHA-1:
5046e19b86cc7ed3188ae804b0672675778427d1

SHA-256:
8f968002db52ff5f5cd0fb2143810476b22bfd716c1c0d0f4b79cb8b222ab49c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/24/2024 7:49:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.4.9

File size:
1.2 MB (1,219,584 bytes)

Product version:
4.0.5

Copyright:
Internet

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\raft_setup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/7/2016 2:28:01 AM

Valid to:
3/8/2017 2:28:01 AM

Subject:
CN=Morava Group, O=Morava Group, L=Towson, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A83F14C1C6D435814D1A4B9EC949DB5C

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9840

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file raft_setup.exe has been seen being distributed by the following URL.

http://www.downloadtourapplication.com/NsT7dWwJvvtXRcdrSyMSvYvTiqHV9fLhvQOP7e9U5s2JMRTAanzY2GiMfIX4qQNJIpHhLFmoIi7LxrHKvV DAWCHGbMgZnWR1f4nazT67Pur_tf4heEcXO72L Hwvb6q1ffgtYVYwvqobMaZKnVBw4KWTQbPk20oolZGzc5JBGiksq1ugsvsLvolSiPKu88Z RJrurLUqW7pVZRxO qcEX9wtBkDmA==-GzoAAETnFhNQIh1CekDHptM5JQgOOXD4Tm1JwBY45IS Q0GWa7y MtEpH4KSE2KfGNr1dyoLQzGDf24=

Remove raft_setup.exe - Powered by Reason Core Security