setup.exe

Installer

Stepitapp LLC

The application setup.exe by Stepitapp has been detected as adware by 12 anti-malware scanners. The file has been seen being downloaded from nym1.ib.adnxs.com and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Stepitapp LLC  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
a54e7992aa83b9c9fa3d979b2bdcddbc

SHA-1:
9f46fdcbc24d5a3b54485459455149d52d183b94

SHA-256:
688aa43789ec94880eebcd5becbad10a41537f5af559bc5036af03805877fec2

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
12/25/2024 5:17:07 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
2014.9-140803

Fortinet FortiGate
Riskware/Agent
8/3/2014

G Data
Win32.Trojan.Agent.4P134N
14.8.24

herdProtect (fuzzy)
2014.9.11.21

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.3462

McAfee
Artemis!EC6559E3952C
5600.7049

Panda Antivirus
Trj/Chgt.C
14.08.03.03

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Stepitapp.F
14.8.3.15

Trend Micro House Call
Suspicious_GEN.F47V0630
7.2.215

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Conduit
31858

File size:
400.4 KB (410,032 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
FinalInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/10/2013 7:00:00 PM

Valid to:
12/11/2014 6:59:59 PM

Subject:
CN=Stepitapp LLC, O=Stepitapp LLC, POBox=1252, STREET=9 W. 31st Street, L=Bayonne, S=New Jersey, PostalCode=07002, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EA7DEF51F4F715C2C81433CCD6B15766

File PE Metadata
Compilation timestamp:
8/1/2014 2:55:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:/3Vo/bClibqI59PpOPf201/z7pHmJI9ftR0l9h7eH:9o/elibqI59Pk2cb7pHmJ0ftR0l/eH

Entry address:
0x621FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1819

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
385 KB (394,240 bytes)

The file setup.exe has been seen being distributed by the following 42 URLs.

http://nym1.ib.adnxs.com/click?21ZUgoIRxj_nOo20VN7CP5qZmZmZmbk_1e-P-K8Pwz_2LvyYPEvGP0sFItwdtLINK9hFawArbgS4uN9TAAAAALdVKQBfAAAAdgIAAAIAAABN7vUAsmkGAAAAAQBVU0QAVVNEANgCWgBuZwAAm7QAAgUAAQIAAJAADSm1WgAAAAA./cnd=!_gbhQgim5vsBEM3c1wcYstMZIAA./referrer=http://us.levi.com/search/index.jsp?view=all/clickenc=http://.../st?cipid=892000&ttype=1&crid=1602718&dast=Ym89MiZjaXBpZD04OTIwMDAmY2lzaWQ9N0E1MUQ5MUFDMTMyNTUyNTE0NDgzNzAzODMmY2lyaWQ9N0E1MUQ5MUFDMTMyNTUyNjY1NDQ4MDM5NiZzbGlkPTAmc3ViaWQ9NTAwMTUwNDIyNTIwMDAwMDAwJmNpdWlkPTc4NjEwNTMyNzk2MTQ1MzY2MDAmc289MiZjcmlkPTE2MDI3MTgmZXhjaWQ9MjImbW10PS0xJmNudHJ5PTIyNyZjaWNtcD0yOTU1NDgmcHViaWQ9NjE5MDg=&cmcv=${CMCV}&tgtf=http://www.mydownloadhome.com/download/201?pub_id=90&sub_id=nym1CKuwl9qG4Iq3BBACGMuKiOHdg63ZDSIPMTYyLjI1My4xNzIuMTk0KAEwuPH-ngU.&tag=2708919

http://nym1.ib.adnxs.com/click?hsTFx1kB5j-GxMXHWQHmP1CNl24Sg9A_hsTFx1kB5j-GxMXHWQHmP3aVLd7PsWx-pc4RnOsYFn80Zu1TAAAAAJf7KAB2AgAAdgIAAAIAAABA7_UAllsGAAAAAQBVU0QAVVNEACwB-gDIDwAAFeYAAgQAAQIAAJAAHypdtgAAAAA./cnd=!xAbGQQit5PsBEMDe1wcYlrcZIAQ./referrer=http://www.vdokhmer.com/watch/town-production/town-vcd-vol-43-07-min-kit-yur-any-zam-video-185142.html/clickenc=http://www.mydownloadhome.com/.../201?pub_id=90&sub_id=nym1CKWdx-C5nYaLfxACGPaqtvH9uay2fiINNzMuMTY3LjEyMi43OSgBMLTMtZ8F&tag=2685847

http://nym1.ib.adnxs.com/click?ct2WuoIf6j8KQtRDoq7lP6JFtvP91AVACkLUQ6Ku5T9y3Za6gh_qPyC6SOQct2ZmAvPv-frxgyLYBApUAAAAABTOMgCTBwAAdgIAAAIAAADrIRwBCmEHAAAAAQBVU0QAVVNEACwB-gDnOgAAyqQAAgUAAQIAAJQAYyn-hwAAAAA./cnd=!pQakPwi027QCEOvD8AgYisIdIAA./referrer=http://countrymusicnation.com/newcomer-derek-anthony-pays-tribute-to-king-george-with-new-song-50642/clickenc=http://www.mydownloadhome.com/.../201?pub_id=90&sub_id=nym1CILmv8-vv_zBIhACGKD0oqLO462zZiIOMjA5LjIxMy4xOS4yMjkoATDYiaigBQ..&tag=3329556

http://lax1.ib.adnxs.com/click?Ar4BajCrREACvgFqMKtEQAAAAAAAgEhAAr4BajCrREACvgFqMKtEQFmf5LysZv8Rc8gLL1gzWl1l4ftTAAAAABEsIgB2AgAAdgIAAAIAAABN7vUAuIYFAAAAAQBVU0QAVVNEANgCWgABYQAAvd0AAgQAAQIAAIwAmB9uSAAAAAA./cnd=!Ogb4OgiW3o0CEM3c1wcYuI0WIAQ./referrer=http://www.download366.com/internet-explorer-10-for-windows-7/thanks/clickenc=http://www.mydownloadhome.com/.../201?pub_id=90&sub_id=lax1CPOQr_iC64ytXRACGNm-kufL1dn_ESIMNjguMTAyLjUuMTc2KAEw5cLvnwU.&tag=2239505

http://lax1.ib.adnxs.com/click?3D66gfBGqT_cPrqB8EapP9nO91Pjpbs_3D66gfBGqT_cPrqB8EapP9cuSs1xzI9uC1XB5qlUkTbCOv1TAAAAACg_KAB2AgAAdgIAAAIAAABN7vUADSYFAAAAAQBVU0QAVVNEANgCWgAW6wAAUL8AAgQAAQIAAI4ASivZbwAAAAA./cnd=!wwYxQQia5PsBEM3c1wcYjcwUIAQ./referrer=lax1.ib.adnxs.com/clickenc=http://www.mydownloadhome.com/.../201?pub_id=90&sub_id=lax1CIuqhbaeldXINhACGNfdqOqcjvPHbiINNzMuMTY2LjM0LjEwMigBMML19J8F&tag=2637608

http://lax1.ib.adnxs.com/click?Ed9BfAfxvT-amZmZmZm5P5qZmZmZmbk_YTOCr9rlwj9zhR0eTxrGPwcanpWufm5L-vN2uhkr33V3y99TAAAAALdVKQBfAAAAdgIAAAIAAABN7vUAsmkGAAAAAQBVU0QAVVNEANgCWgBuZwAAxK0AAgUAAQIAAJAAlCnnTgAAAAA./cnd=!_gbhQgim5vsBEM3c1wcYstMZIAA./referrer=http://jqp.toolspre.net/sd/dw32.html?u=http://ugo.tractionize.com/WhiteLabelBidRequestHandlerServlet?oid=1&width=1&height=100&pubid=1700&tagid=1049&noaop=1&revmod=CRD&cb=cybabw&encoded=1&cirf=http://congratulations-you-won.claimprizenow.com/us/j/440/1212.html&pstn=17001049/clickenc=http://.../st?cipid=892000&ttype=1&crid=1602718&dast=Ym89MiZzbGlkPTAmc3ViaWQ9MjAwMTE3MTIyNTE1MDAwMDAwJnNvPTImY2ljbXA9Mjk1NTQ4JnB1YmlkPTUyODAwJmNpcGlkPTg5MjAwMCZjaXNpZD1FMzM1QTgyMTQxMzQ1NDc5MTYwNTIxNTE1MCZjaXJpZD1FMzM1QTgyMTQxMzQ1NDgwMTMwOTM5MzM2MSZjaXVpZD02NTg1MDQxMzkyNTY5MzA3MzEzJmNyaWQ9MTYwMjcxOCZleGNpZD0yMiZtbXQ9LTEmY250cnk9MjI3&cmcv=${CMCV}&tgtf=http://www.mydownloadhome.com/download/201?pub_id=90&sub_id=lax1CPrn29Ob48rvdRACGI

Latest 30 of 42 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security