setup.exe

LLC

The application setup.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from cdn.freefacta.com.
Publisher:
LLC   (signed and verified)

MD5:
0b118a88e7d657c4c1e940ad4b3c2dc7

SHA-1:
79f4c5199d8e75866f258ecdf64dcaa9bb329bd6

SHA-256:
999429bf3e488ff5133182178f9ae4c103d311c22bd8e2160409b5c05f37a5e3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 5:17:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize.Installer (M)
16.3.27.1

File size:
230 KB (235,512 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/4/2015 9:00:00 PM

Valid to:
4/4/2016 8:59:59 PM

Subject:
CN="LLC ""Gran-Proyekt""", O="LLC ""Gran-Proyekt""", STREET="Mikhayla Grushevskogo str., 41", L=Odesa, S=Odeska, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EFDB75E08F6888C2E97C8F77D9190669

File PE Metadata
Compilation timestamp:
8/6/2015 1:07:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:nlHBjcY8gIJf6fC46K2lac3/O1qQmbPNriS4sELP3wdb27BXc1f:nrA3gQiCrPFiYELab8BG

Entry address:
0x8444

Entry point:
E8, 2B, 7A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 95, 42, 00, E8, A6, 10, 00, 00, E8, FC, 7B, 00, 00, 0F, B7, F0, 6A, 02, E8, BE, 79, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, B4, 3A, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
126.5 KB (129,536 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security