Setup.exe

ShortSetup

Installer Technology Co.

The file Setup.exe has been detected as malware by 1 anti-virus scanner. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from installopensoftware.com.
Publisher:
Installer Technology Co.  (signed and verified)

Product:
ShortSetup

Version:
4.1.0.1

MD5:
798aafdec009561b04dc80c8657aaa21

SHA-1:
7a3ed40ca5d45533bbe921735c347733ba0036a7

SHA-256:
6001846bc31f133353d73b57429f6157f7cc75d5149697542f52f48152edcbe3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/27/2024 2:50:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.13.3

File size:
131.5 KB (134,608 bytes)

Product version:
4.1.0.1

Copyright:
Copyright 2016

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/5/2017 7:00:00 PM

Valid to:
1/11/2018 7:00:00 AM

Subject:
CN=Installer Technology Co., O=Installer Technology Co., L=miami beach, S=Florida, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
028EAD1A1B4B5B91CC8CC45FD612ADD7

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.2581

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file Setup.exe has been seen being distributed by the following URL.

https://installopensoftware.com/campaign/.../rdr.php

Remove Setup.exe - Powered by Reason Core Security