setup.exe

The executable setup.exe has been detected as malware by 1 anti-virus scanner. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from i.funmoods.com.
MD5:
45e0153956fce8618bade8b5b06a20ad

SHA-1:
22a7fdea84353ab5fc6220ad3e1d1489dd21ca27

SHA-256:
c55ae2c9965b62842750022ef9cadb5c66f6951cbf65c96a3bb6d3833dfde02e

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/5/2024 6:34:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.5.5.13

File size:
1 MB (1,075,800 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:gFNfPCs0KKd/j7seLcblXNA0k1TQevNEF:gvfPN0dr7RQbZ21TTvN4

Entry address:
0xC2230

Entry point:
55, 8B, EC, 83, C4, F0, B8, C2, 17, 40, 00, E8, 24, EC, FF, FF, 28, 12, D0, 33, A2, 90, 93, 61, ED, 1F, D3, 8C, 3F, 09, 3C, BD, AF, 7C, DA, B6, 61, 6E, 82, A4, 43, 8D, 8B, 90, BA, CA, 5B, B0, BE, 28, 61, 06, 40, C9, 6E, C9, D4, 92, 9C, 9C, FA, B8, 29, 80, 8D, 12, F7, 10, 1D, 1E, 9D, 73, 4E, FE, 31, 09, 79, DB, 37, C9, 2B, 77, 68, D4, 39, E1, 38, B5, 8E, 96, 41, 3C, EC, 71, 0F, 12, 30, 42, E4, 5B, EA, F3, 77, 04, 57, 86, C3, 97, F9, 59, 69, B7, 71, 7D, 36, 9B, 4F, 0F, DB, 23, F8, CF, E0, 68, DF, 82, 57, E0...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
786.5 KB (805,376 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security