setup-71202513.exe

Garden Variety Media

The application setup-71202513.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from cdn1.drivereco.com.
Publisher:
Garden Variety Media

Product:
Garden Variety Media

Version:
10.9.2.720

MD5:
e2eb31dac26a85a5809778a5a5043c58

SHA-1:
b8dc2dbcc277b257623d2b9f5b069a6ce6d6ed1c

SHA-256:
41fd93dc726b94e2c0d738a387210c5b73464b028ba0198a35f42538023cfe2e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 9:27:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.DownloadAdmin (M)
16.3.27.7

File size:
970.4 KB (993,712 bytes)

Product version:
10.9.2.720

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup-71202513.exe

File PE Metadata
Compilation timestamp:
3/8/2015 12:16:57 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:bYMwiNRmchkR20bPsIU/fpvWkuasz8xz2WyAknYQ1WpSZaStcg5d1bUqST2JXC6P:bIiNEchkc0bkZfAV8xz2WyAknYQ1WpSJ

Entry address:
0x1066

Entry point:
8D, 3D, F3, C0, 61, CB, EB, 06, 81, D8, 34, 94, 4B, FD, 87, CA, BB, FD, 8B, 6E, 3A, F7, DA, E8, 17, 00, 00, 00, 8D, 15, FA, CC, 6D, 2C, 78, 09, 69, EF, 53, DE, C6, BB, 0F, AF, FF, 03, F0, EB, 02, FF, CF, 5E, F6, D9, F6, D2, 3B, EF, 0F, B6, D0, 81, DF, 4F, 85, F2, A4, 4F, 70, 08, 0F, BF, FA, BF, A6, 0E, 73, E0, BD, A7, D6, 17, 00, 8B, FE, 81, F5, 74, 88, 00, 00, 77, 07, 0F, AF, FD, F7, D7, 8B, FA, 0F, AF, F8, F7, C3, 5A, 08, 2F, 1A, 68, 6E, 0E, 00, 00, 5F, 81, F7, 74, 03, 00, 00, 57, 76, 02, F7, DA, 5A, 0F...
 
[+]

Code size:
57 KB (58,368 bytes)

The file setup-71202513.exe has been seen being distributed by the following URL.

Remove setup-71202513.exe - Powered by Reason Core Security