setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Digital Plugin SL has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from docs.fastenyourdata.com.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
f84f28103c254cf636bd65f1d12dc41d

SHA-1:
77d4ae90d4766852cd04d2b57f391ce8966e3ff8

SHA-256:
c78e3dac8a6bdf02f15e6c3e3267c26df17e7e23bd95bb2d128a4900c96eb47f

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 12:18:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.SoftPulse.P
461

Agnitum Outpost
PUA.SoftPulse
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.10.30

Avira AntiVirus
PUA/Softpulse.Gen
8.3.2.2

Arcabit
Application.Bundler.SoftPulse.P
1.0.0.585

AVG
AdPlugin
2016.0.2939

Baidu Antivirus
PUA.Win32.SoftPulse
4.0.3.151031

Bitdefender
Application.Bundler.SoftPulse.P
1.0.20.1520

Bkav FE
W32.HfsAdware
1.3.0.7383

Clam AntiVirus
Win.Adware.Softpulse-208
0.98/21511

Dr.Web
Trojan.Domaiq.383
9.0.1.0304

ESET NOD32
Win32/SoftPulse.AJ potentially unwanted (variant)
9.12485

F-Secure
Application.Bundler.SoftPulse
11.2015-31-10_7

G Data
Application.Bundler.SoftPulse
15.10.25

K7 AntiVirus
Unwanted-Program
13.212.17693

Kaspersky
not-a-virus:HEUR:AdWare.Win32.SoftPulse
14.0.0.1192

Malwarebytes
PUP.Optional.SoftPulse
v2015.10.31.01

MicroWorld eScan
Application.Bundler.SoftPulse.P
16.0.0.912

NANO AntiVirus
Riskware.Win32.SoftPulse.dydypc
0.30.26.3947

Panda Antivirus
Trj/Genetic.gen
15.10.31.01

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
1.0.0.1015

Quick Heal
PUA.Digitalplu13.Gen
10.15.14.00

Reason Heuristics
PUP.Softpulse.DigitalPlugin.Bundler (M)
15.10.31.13

Sophos
SoftPulse (PUA)
4.98

VIPRE Antivirus
Adware.SoftPulse
44896

Zillya! Antivirus
Adware.BrowseFox.Win32.128684
2.0.0.2480

File size:
1.2 MB (1,242,120 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/7/2015 10:00:00 PM

Valid to:
1/8/2016 9:59:59 PM

Subject:
CN=Digital Plugin SL, OU=606372162, O=Digital Plugin SL, L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
09630EF45908E3288578DD4139725FDD

File PE Metadata
Compilation timestamp:
10/23/2015 8:38:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:yDfYjzMGFC975ZsalP8G7RKxXB0xE36T27xomZ:6fQBFC9dGaJYd36T27xoA

Entry address:
0x47A7E0

Entry point:
60, BE, 00, 70, 75, 00, 8D, BE, 00, A0, CA, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, D0, 8D, 47, 00, 57, 83, C3, 04, 53, 68, D4, 37, 12, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
1.1 MB (1,200,128 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security