Setup.exe

OSU

Traffic Space, LLC

The file Setup.exe, “Open Software Updater” by Traffic Space has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from flv.hs1dmr.com and multiple other hosts.
Publisher:
Installer Technology Co  (signed by Traffic Space, LLC)

Product:
OSU

Description:
Open Software Updater

Version:
3.0.0.0

MD5:
05f85ba7d6253eb2337133d5c8e91aae

SHA-1:
8518910d6c341908bfe2b42e62c2bf7e58060a65

SHA-256:
463f160fd5f2d8d511385e2f59dfef0c58bae6de894116923c4723ba3584581e

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
11/27/2024 4:11:01 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.9973
9.0.1.072

ESET NOD32
Win32/Packed.VMDetector.Q potentially unwanted
9.11313

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.TrafficSpace
15.3.13.16

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15311

Trend Micro House Call
Suspici.326C0565
7.2.72

File size:
319.6 KB (327,256 bytes)

Copyright:
Copyright Installer Technology Co. 2015

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/10/2015 4:00:00 PM

Valid to:
3/18/2015 4:59:59 PM

Subject:
CN="Traffic Space, LLC", O="Traffic Space, LLC", L=Woodcliff Lake, S=New Jersey, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1C74C364E85C31C63BF0EFB6F416FD6A

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:3QqkDtiik3QQLjqC4+mjEd5C7sbKN2ja89jCP+Ys52r6O6AQgz6dy:uEifQ6C4+DjmNp8FCP+Ys52r6OOgz6E

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8202

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file Setup.exe has been seen being distributed by the following 4 URLs.

http://flv.hs1dmr.com/aff_c?offer_id=44&aff_id=1020&url_id=166&aff_sub=754--943--1385124984.4186--88de4b85f2&cb=88de4b85f2

Remove Setup.exe - Powered by Reason Core Security