setup.56984.exe

The application setup.56984.exe has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a setup program which is used to install the application. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.softsoft.ru.
MD5:
365a3d1c636af17f12bda8b98c773138

SHA-1:
0dbfd35c74d7bbc2bc72505dfc932292951c0d3d

SHA-256:
643bac4d4f464aa828f8021d8c8eb0cdd49a31f24cc09a1ce45e261258b4d904

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/30/2024 10:57:21 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2013.06.24

Avira AntiVirus
7.11.86.82

avast!
Win32:Ivelog-Z [Trj]
2014.9-160501

Comodo Security
UnclassifiedMalware
16481

Dr.Web
Adware.InstallCore.82
9.0.1.0122

ESET NOD32
Win32/InstallCore.AZ (variant)
10.8481

F-Prot
W32/InstallCore.I2.gen
v6.4.7.1.166

G Data
Win32:Ivelog-Z
16.5.22

IKARUS anti.virus
Win32.Ivelog
t3scan.2.0.3.0

K7 AntiVirus
Unwanted-Program
13.170.8903

Panda Antivirus
Suspicious file
16.05.01.06

Reason Heuristics
PUP.InstallCore.ENG (M)
16.5.1.6

Trend Micro House Call
TROJ_GEN.RCBH1BP
7.2.122

VIPRE Antivirus
Trojan.Win32.Generic
18976

File size:
1.1 MB (1,148,120 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.56984.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:hl87bI+Hk9ORDlGkPaKaAolbPddrv/m7vnSbt4dsOG1+siW6oPI1e:h6c+E94GkSZHpEnSbtxMsiW6s

Entry address:
0xD5880

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, 62, 40, 00, E8, 47, DE, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)

The file setup.56984.exe has been seen being distributed by the following URL.

Remove setup.56984.exe - Powered by Reason Core Security