setup.exe

bundlebeez ltd.

The application setup.exe by bundlebeez ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Installer  (signed by bundlebeez ltd.)

Product:
Installer

Version:
1.48.0.0

MD5:
f718e242a14c9582dd84b84234e05962

SHA-1:
07e932ab7772b8c3f421e73ed3dd39ba4fb206a7

SHA-256:
73d7aa088b263dc66a9ed8488a1e35abe9b2840bb15f20ff9ec5eb0f1f2a0f30

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/15/2025 1:14:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.1.6

File size:
407.6 KB (417,392 bytes)

Product version:
1.48.0.0

Copyright:
Copyright (C) 2014

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/8/2014 7:00:00 PM

Valid to:
12/9/2015 6:59:59 PM

Subject:
CN=bundlebeez ltd., OU=bundlebeez, O=bundlebeez ltd., STREET=1 habarzel st., L=tel aviv, S=israel, PostalCode=69710, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C76FF2C3632486922817A7EBE894CE9E

File PE Metadata
Compilation timestamp:
1/20/2015 11:16:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x118D60

Entry point:
60, BE, 00, 70, 4C, 00, 8D, BE, 00, A0, F3, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8929

Packer / compiler:
UPX 2.90LZMA

Code size:
328 KB (335,872 bytes)

Windows Firewall Allowed Program
Name:
isdm


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security