sedif_setup1.0.3.43.exe

SEDIF-SN

ICP-Brasil

The application sedif_setup1.0.3.43.exe, “SEDIF-SN Setup ” by ICP-Brasil has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.sedif.pe.gov.br and multiple other hosts.
Publisher:
SEFAZ   (signed by ICP-Brasil)

Product:
SEDIF-SN

Description:
SEDIF-SN Setup

MD5:
302fc6fd3ca04a6390b90719cf85e072

SHA-1:
18d99bfe16506451afb7e7e4e7e642c5aa651106

SHA-256:
1cae41a5c9dc7d601e61b1d68f3d4c7c467dfb3417845fc90c5bf5482c7cc91d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
2/26/2025 2:07:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.14.19

File size:
32.8 MB (34,345,832 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\sedif_setup1.0.3.43.exe

Digital Signature
Signed by:

Authority:
ICP-Brasil

Valid from:
1/5/2016 9:00:00 PM

Valid to:
1/4/2017 8:59:59 PM

Subject:
CN=SECRETARIA DA FAZENDA:10572014000133, OU=Autenticado por Certisign Certificadora Digital, OU=RFB e-Codigo A1, OU=Secretaria da Receita Federal do Brasil - RFB, O=ICP-Brasil, C=BR

Issuer:
CN=AC Certisign RFB G4, OU=Secretaria da Receita Federal do Brasil - RFB, O=ICP-Brasil, C=BR

Serial number:
0A6D334D270C79A492F623E0EF8D3551

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file sedif_setup1.0.3.43.exe has been seen being distributed by the following 2 URLs.

http://www.sedif.pe.gov.br/.../sedif_setup1.0.3.43.exe

http://downloaddestda.fazenda.sp.gov.br/.../sedif_Setup.exe

Remove sedif_setup1.0.3.43.exe - Powered by Reason Core Security