Setup.exe

Code Techno

The file Setup.exe by Code Techno has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from clkads.com and multiple other hosts.
Publisher:
Code Techno  (signed and verified)

MD5:
c32ec4cb813815f679bfc9138ec0d3b9

SHA-1:
3913a1c5537a7cc07f1c95812b1c1343d0db7646

SHA-256:
033ce2bec462e34305d0e29734c5eedccdb01d97ff31814e4b3ecda002b08e62

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 4:32:41 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Downware
2014.12.14

Avira AntiVirus
ADWARE/Adware.Gen
7.11.195.56

AVG
Generic
2016.0.3102

Clam AntiVirus
Win.Adware.Downloadadmin
0.98/21511

Dr.Web
Adware.Downware.2220
9.0.1.0141

ESET NOD32
Win32/DownloadAdmin (variant)
9.10872

G Data
Win32.Application.DownloadAdmin
15.5.24

IKARUS anti.virus
Trojan.Dropper
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.187.14319

Malwarebytes
PUP.Optional.DownloadAdmin
v2015.05.21.11

NANO AntiVirus
Riskware.Win32.Downware.djahkt
0.28.6.63850

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.CodeTechno
15.5.21.23

Sophos
Generic PUA DJ
4.98

VIPRE Antivirus
DownloadAdmin
35690

File size:
821.2 KB (840,936 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2014 7:00:00 PM

Valid to:
2/25/2017 6:59:59 PM

Subject:
CN=Code Techno, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Code Techno, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
57F2A4C1987266C5627CFFB542729A0B

File PE Metadata
Compilation timestamp:
7/15/2014 11:29:31 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:rxpJfslZtuaVd9lpmhwQbift489IVGD4xJFl6Xqb5Kbmkg8Sx:lp9sVuaVdvgVbmgGDijyikg5x

Entry address:
0x3345

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2E, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1F, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0D, 24, 00, 00...
 
[+]

Entropy:
7.4890

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file Setup.exe has been seen being distributed by the following 2 URLs.

http://clkads.com/adServe/adClick?ai=e78pZMpPz6QRHbtzjsPZ74alAwPUtQGsPqOJT4se1fndHbMPjmpql0LtzGNhwFrXsN9FckUmkyXb eBvKOJIRtxhjoy5UJpg1QDfyK1vval2QTV8qnt5/ uuDweths7eKyPSZZi1xbUadI1eTxfLOZT3K kT6wy04WBpoOL IGFAUwra98siXOwYQumcnxa2Owy6nLSy3dZqbuLljrvxIndVTWdrrb0 Pm2i02 BUyBpnVXMM607FlrOY 7mICB5lTaw9/.../p70cSUAeGIZUHHbM4WKZbExsSdXptNTbBTURpFa 0 yExrHA==&ui=QUOaLjelBQi9LwDJaIorklY37AsT2Aewo7EMJaH1qg5uSdCnws0HUe 5a0ZMKUWk&src=BANNER

Remove Setup.exe - Powered by Reason Core Security