setup.exe

Soft Internet

Install Fall

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application setup.exe, “Soft Internet Setup ” by Install Fall has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdn.broadappshub.com.
Publisher:
Internet Web generic   (signed by Install Fall)

Product:
Soft Internet

Description:
Soft Internet Setup

MD5:
231f0b29a7f335482daadae84c5b20bf

SHA-1:
305b47c19cf2465d0b07cd50206362c65959f777

SHA-256:
e8e4b6ef2ba5e5e1aae2ea4c12761ae6012d8b7c91f3212e241d0d149c24dbd9

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 9:47:10 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/InstallCore.Gen
8.3.1.6

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.iBryte.556
9.0.1.023

ESET NOD32
Win32/InstallCore.ZM potentially unwanted application
10.7.0.302.0

K7 AntiVirus
Adware
13.204.16151

Reason Heuristics
PUP.InstallCore.Adknowledge.Installer (M)
16.1.23.12

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4798837
40828

File size:
677.2 KB (693,408 bytes)

Product version:
5.5.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/6/2015 4:00:00 PM

Valid to:
1/7/2016 3:59:59 PM

Subject:
CN=Install Fall, O=Install Fall, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=MO, PostalCode=64112, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0083B4E0983693C2A446B5467ACFC57E11

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:+k6xG2qVZvWJsNaCvB/oMdz/uZOcQIsXyozdqeiW2SsW0Y0DwrVQZG2TFCQSn1YQ:+5x7qVZ4grxoMp22XZz5iWxsW0YFZQ6x

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8824

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security