Setup.exe

Setup

Elex do Brasil Participações Ltda

The file Setup.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 6 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from s2s.yac.mx and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
Setup

Version:
1.0.154.23394

MD5:
ff4812aa6342a601b76b4cd496b5388f

SHA-1:
7ac0f326c03f97a3b29bc5e5308b1707a7ce6a15

SHA-256:
7ca54e22d80b778d5ae1ef0e959eb6d1be9ef3a2622cb261e3c9fcc94bafbce9

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 10:50:48 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Mutabaha.174
9.0.1.072

ESET NOD32
Win32/ELEX.CC potentially unwanted (variant)
9.11312

Fortinet FortiGate
Riskware/Elex
3/13/2015

McAfee
Artemis!FF4812AA6342
5600.6828

Reason Heuristics
PUP.Optional.Installer.ELEX
15.3.13.3

Trend Micro House Call
Suspicious_GEN.F47V0312
7.2.72

File size:
847.8 KB (868,176 bytes)

Product version:
1.0.154.23394

Copyright:
Copyright (c) 2011-2015 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2014 4:00:00 AM

Valid to:
6/21/2015 3:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
3/11/2015 10:02:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:SjC2VVb/1DX/gQ71s3wC1/Thz3dDeHVTGQT4fPn3OBqIUEpl1NYJBW9sdz8i:ILV917YP3Jz3diVTGQJnUKzZidz8i

Entry address:
0x93B8

Entry point:
E8, 41, 40, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, FF, 15, 90, 60, 41, 00, 6A, 01, A3, AC, EE, 41, 00, E8, 2C, 45, 00, 00, FF, 75, 08, E8, C1, 44, 00, 00, 83, 3D, AC, EE, 41, 00, 00, 59, 59, 75, 08, 6A, 01, E8, 12, 45, 00, 00, 59, 68, 09, 04, 00, C0, E8, 8F, 44, 00, 00, 59, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 11, 70, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, 90, EC, 41, 00, 89, 0D, 8C, EC, 41, 00, 89, 15, 88, EC, 41, 00, 89, 1D, 84, EC, 41, 00, 89, 35, 80, EC, 41, 00, 89, 3D, 7C...
 
[+]

Entropy:
7.5544

Code size:
83.5 KB (85,504 bytes)

The file Setup.exe has been seen being distributed by the following 40 URLs.

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=lL_PDWpmNWqVUEXXKEHLEF45mheDHbCO2Uj_I5m_Cw9oJdfvVhD8_zJo3DaJMHpboqtJlZ2oQFzbzQkrQq6VCRMRpTCERR4kDgG_miVLMu_uPxFCRJYgJAsTqMJfwn4Csda86m3YoC_bb-L3WQFWLFIbqNmWe02gPoDtRSxky7nq1lmmOv8NyV6UD_taF0Ft0qH-teYYGhzDvCzJhqLz4RG2n_q9fjCNl9KT4QNJToRk9pHCBzNs7YVF1ECEpFZaD9kap0sgs65Qqw4jEE9ILTRWEVkVJCf49fkX2X9zp4TKylKvqKmDZ7qbghFZgMkrKci6ycbwfxp3jm2LYYnEpbtk-BqXWSjXwjNiqluXx1IKpun4X5Pa-AWr2nugtpigSuulo4KooPe4cHifAnFPCHa8s7S3l6-W3oDIyeoDrYkJPy1p&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=HWSG-0TVtvmg62GRli-5WDU3xd43GQdKiy_Gg4hnAEQAWOHnYAK_KpCD-qJt_eT16gl3M2aHMW1rdUn9snYwgWN-Xk8q_iJPuuISBxFliN5MOqbfWxZ1GlHhHYMKBeg4pv6GtsaQWhSE0ndO1nG5HgAOeVcSxQIAcpUXU-HgGcg8py-bUpHcpe_aCTY3BKz28dWYHDdEWNiP9yPXbV8p7_6e249xTcSukW8z3vtGE_Uzs7Hq7uv-VX3fQUSj9Yw3uYfenvAGTKGpnrL1bqbZqajQOHrm9V_21qNlSUR4tnLpqxEVoa-RFfLd7a_Zz6CYlLDzluM-wBube9fSwf0IOmz7arc5Oof84MgU9D7x5ZI9arvniVq8qYn0s9rpsH_fV1BXmNBA5Ap30olzZaDQYbzydvVX7otmylf_rXCcAEjUZZyvYg&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=avae&subid=10624507650

http://www.yac.mx/download/.../down.php?pt=gam&subid=20421

Latest 30 of 40 download URLs

Remove Setup.exe - Powered by Reason Core Security