setup.exe

The executable setup.exe has been detected as malware by 7 anti-virus scanners. The file has been seen being downloaded from zenmate-windows-update.s3-eu-west-1.amazonaws.com.
MD5:
a6dcf9649463b2b1d96e08b7280f67d1

SHA-1:
4fb03e23a136bda5b40e49e25f0a16f1c9ea2f65

SHA-256:
862b6fdd041815f32bd04aa0e93fe80c699f84249579a82eab7698390af247c3

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/25/2024 12:26:35 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:AutoRun-CWJ [Trj]
160414-2

Dr.Web
Trojan.Siggen6.55368
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.KDV.391478
11.5.0.6191

ESET NOD32
Win32/AutoRun.Delf.LV worm
7.0.302.0

F-Prot
W32/Autorun.ZF
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.850.0

Norman
Trojan.Generic.KDV.391478
28.05.2016 15:32:18

File size:
824.5 KB (844,288 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
8/9/2011 12:51:42 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:1wCBtLC+EptUpQ9SeSChq3YvxFBSSRMT8PTp4ehozELz888888888888W888888E:ZNzCtUpQ9WWPBSSRMTEpXNLH

Entry address:
0xABD46

Entry point:
B9, 88, 42, 00, 00, 14, BD, EB, 0B, 00, 00, 00, 00, 05, C6, 00, 1A, 51, 00, E3, 80, EC, 8B, 39, C8, 85, C2, 8D, 95, 73, 26, CE, DA, 86, E6, F6, D2, F8, 81, A9, 00, A4, 4D, 00, 33, 09, F6, 84, EB, 9F, 00, 00, 00, BF, C9, 54, D0, 49, 66, 50, 00, 04, 89, 52, DD, 44, 4B, 4A, 81, 13, 00, 65, F1, 5C, 6C, 00, 26, 84, C8, FE, 5C, 0E, 6C, F6, 3B, 00, 55, A6, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.5193

Code size:
682.5 KB (698,880 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security