setup.exe

CONCEPTION SELECTION DISTRIBUTION INTERNATIONALE

The application setup.exe by CONCEPTION SELECTION DISTRIBUTION INTERNATIONALE has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dl.clean-navigate.com. While running, it connects to the Internet address csdi-track1.clean-navigate.com on port 80 using the HTTP protocol.
Publisher:

MD5:
1e1a620af92f3aeef7e2ce2063694462

SHA-1:
72842e9b81bf9193ee2007c53c38ced3d6959064

SHA-256:
5f827a8a26287a8df8f5a73e887d9585cf644f3631e96a72ecb1d89c3d6dddc4

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:34:47 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
2014.9-150617

AVG
Generic
2016.0.3076

ESET NOD32
Detection.Undefined
7.0.302.0

Reason Heuristics
PUP.Optional.Installer
15.6.15.13

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
5 MB (5,193,216 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2014 2:36:07 PM

Valid to:
12/17/2015 2:36:07 PM

Subject:
CN=CONCEPTION SELECTION DISTRIBUTION INTERNATIONALE, OU=Xhopever, O=CONCEPTION SELECTION DISTRIBUTION INTERNATIONALE, L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112106B28CB2E4D8370E3EC157B3C5B3FF12

File PE Metadata
Compilation timestamp:
10/7/2014 6:40:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:fMPvAtCYeQepWX8MJ2xnmBFDaajNFAuhRbLtl4Djpp4X57:fMPvfJRc+xnmq6NeuhRbLtl4HwX57

Entry address:
0x30E2

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 1C, 71, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, 78, E4, 42, 00, E8, A8, 2D, 00, 00, A3, C4, E3, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 00, 88, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, DB, 42, 00, E8, 52, 2A, 00, 00, FF, 15, 20, 71, 40, 00, BD, 00, 40, 43, 00, 50, 55, E8, 40, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to csdi-track1.clean-navigate.com  (37.187.163.75:80)

Remove setup.exe - Powered by Reason Core Security