setup.exe

The executable setup.exe has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from sp-storage.spccint.com and multiple other hosts.
MD5:
e1e43a32da61f1b5425d1000460c91eb

SHA-1:
4aaf8abc739fb802dceb25272eac9f7d2b1486f7

SHA-256:
c533268a320b298b6ded34afb3616a395ca2fe97cd1aa5a1270ed8e00577506f

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/4/2024 8:11:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
(M)
16.6.6.23

File size:
539 KB (551,917 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12288:XaGBxiopMXBVG/OifbCP8wvT4obYppcXh8fssYK1YMig2Y5GtjvrpX3g4:3xiOSBVG1j0L4lnyXMLGtLFX35

Entry point:
E3, C5, 4A, FD, 82, D5, 91, 6F, F4, D6, D0, 58, CA, D6, 13, BF, D9, 4B, EC, 53, 7F, 9C, E3, 54, AF, 88, 93, CB, 50, 44, 15, 51, C5, 37, AC, 25, 9A, 9F, DF, 49, AB, 8D, 62, E2, 5B, 01, 8E, 1E, 8A, 1B, 41, 4A, 7C, 9B, 56, F1, D8, 35, 2D, 1F, 65, 68, E3, 21, 4E, E3, 22, 68, E2, A6, C9, 5B, 3E, 64, C2, 48, 56, E2, BC, BA, 2C, 45, BB, E5, 47, 98, 99, F5, B8, 00, F7, 60, 2D, 57, 3D, 9E, E5, 32, 9B, D9, 9A, 83, 34, 75, 9B, 5F, DE, 8E, B0, 9C, 2D, C4, 8F, 45, A5, FA, 30, 5E, 5B, 92, 03, 07, 05, 06, 07, 0C, 09, 0A...
 
[+]

Entropy:
7.7006  (probably packed)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security