setup-x86.exe

The executable setup-x86.exe has been detected as malware by 7 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.cygwin.com.
MD5:
d1f7be5b538ae54e1741fceece3892d3

SHA-1:
9e62599a8311e47e49db98188ec9960063b7bcca

SHA-256:
60fdd230a247c801a1f7c50228dfd6075224c3dbdb0270f47b176f09b765ad62

Scanner detections:
7 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/27/2024 5:42:34 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

Emsisoft Anti-Malware
Win32.Sality
16.07.17

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.1489.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
896.5 KB (918,016 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup-x86.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:CYdYAXx94nVLbdtzTu11Gva70Ytw3BTE:tdFTovnTuD8eyB

Entry address:
0x29B380

Entry point:
85, C6, FE, C3, F6, C3, 76, 46, F2, 53, 68, 76, E2, 23, 00, 85, DA, F6, C6, 0C, 18, C6, E8, 85, 00, 00, 00, 72, 05, 38, C9, 0F, AF, C7, 88, D0, 46, 8D, 15, 4A, E8, 00, 00, 84, D8, FE, C5, 69, F7, 8A, 4A, FD, B4, 81, EA, 6F, 03, 00, 00, B3, 34, 0F, BE, D6, 85, C7, 73, 05, B2, 63, F6, C0, BE, EB, 07, 0F, AF, C1, 88, E0, B7, DA, 6B, ED, 00, BF, 94, 11, 68, 90, 81, C5, 56, 06, 00, 00, 01, F6, 81, ED, 38, 01, 00, 00, 69, DF, DC, 88, A6, 94, 0F, AF, DB, 42, 0F, AF, CF, 0F, AF, F1, 13, C8, 69, D5, B7, 63, BD, 23...
 
[+]

Entropy:
7.9563  (probably packed)

Code size:
752 KB (770,048 bytes)

The file setup-x86.exe has been seen being distributed by the following URL.

Remove setup-x86.exe - Powered by Reason Core Security