setup.exe

BluPak Software LTD

The application setup.exe by BluPak Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from 7dnyoq8c3onged.teeptip.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Installer  (signed by BluPak Software LTD)

Product:
Installer

Version:
1.48.0.0

MD5:
85f9cc5feb328edc2aae152ee4ee8dc8

SHA-1:
819b6eee7f17486120209efe7379bf193ed9e22c

SHA-256:
56fb3cf451971febde3cbfc35884b202a43837389cf198b0e716c1350e3d9c9b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 2:10:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.17.0

File size:
409.3 KB (419,152 bytes)

Product version:
1.48.0.0

Copyright:
Copyright (C) 2014

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/20/2014 4:00:00 PM

Valid to:
11/20/2016 3:59:59 PM

Subject:
CN=BluPak Software LTD, O=BluPak Software LTD, STREET=42/8 Shderot Bialik str., L=Ramat Hasharon, S=Merkaz, PostalCode=4720816, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DBF6B664AFF218F47D230FAAACD82EBB

File PE Metadata
Compilation timestamp:
12/30/2014 12:08:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x118D40

Entry point:
60, BE, 00, 70, 4C, 00, 8D, BE, 00, A0, F3, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8926

Packer / compiler:
UPX 2.90LZMA

Code size:
328 KB (335,872 bytes)

Windows Firewall Allowed Program
Name:
isdm


The file setup.exe has been seen being distributed by the following URL.

http://7dnyoq8c3onged.teeptip.com/.../?p=ZXh0c3lzPTEmYWZmaWQ9MzAzNjkyJmNpZD0xMDAmY3I9MTAwJmxvYz1lbiZzMT0yNDM1JmFmZmlsaWF0ZXJlZmVyZW5jZWlkPTE0MjIxNzczODltYjUwMDgwNDU2NjE3JmNhbXBpZD0yODI0NTY=&Ft02=hRm3RsBIFGtAHyzoG6jRiV19ogmym65AD2ofTGXEBpaF1EpZV1KIjjUvZnPLgdwIK36PjtEajPp2VvhT0wMuvwquh2pG0mxy2B58HJPBwKzE31KEf6UTBcmoNMHqe8j6r19tAjlrQk7V7VBqsVB4BO60oRv5bzxyACnb1re5UDcqeBq1lr8sGpFM4ieTYqprXIuEIzybQFj8LQWXADUUAe2k6KgSmvhEnVDFhVtV26LagHbowrsuFF0SQjH8tQYvxPU0nqPOk91EC1ezI2v5cX8R4UY7ouBmhpNAWkbgLOjGOwpZeizBu3tKQc6CBSAZHOwmoNNy0ptxNCdIF92f5a2o6cUToIO3nu8aadLBFaKeJ66n9y7CZu4GVhql33jrLAjtEdHCyBK4AYOagHU0Lme3ABo2WzHL0sDjWMT60EdxU9g7DqfwjtQywq3cYPP838diuEnDXXagiQjAvqyFulCHMeXFTQhlZeDV58M8cMIvtJqPhCRHqjORGGFqRSThQYrdmxEwOACRNhndXhyq8J4PzVpzCvru2APErnCT7u30Q7eysCCKtDig4MNBif4siiZnBTVKOOsNQe8CR0h93RbysIKPJbL2ALRIh17IR25PkEAZOkTr84zBgA43igaMdAnfxzv03IsaVvoXhVbzst4FlpBQ6dAK1sMUrvCoZ3yzMyQVmhVxfLuTGR3h7O4ZiRjCTDGWtWKy4E3XJQEYscFq82oJCurk9Jr5pnbSK8esb6YcXfHqkfGfl2E1p6u8Fzzvm8IwPVnt7npcelVwXa93clTwTkCOOgX

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security