Setup.exe

OSU

Hudson Exchange Group, LLC

The file Setup.exe, “Open Software Updater” by Hudson Exchange Group has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from urlology.blob.core.windows.net and multiple other hosts.
Publisher:
Installer Technology Co  (signed by Hudson Exchange Group, LLC)

Product:
OSU

Description:
Open Software Updater

Version:
3.0.0.0

MD5:
d7b45935f43ae38f0a46b63ef3760560

SHA-1:
a178b499560991b50971747f71228bd9ccc0f2b4

SHA-256:
3dd69f23a19d28060ddda88b88b7480320d7319034556d89a8ecde5c4b86140d

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 3:52:59 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM40.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.HudsonExchangeGroup
15.5.3.0

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15405

File size:
457.1 KB (468,072 bytes)

Copyright:
Copyright Installer Technology Co. 2015

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/10/2015 6:00:00 PM

Valid to:
10/31/2016 6:59:59 PM

Subject:
CN="Hudson Exchange Group, LLC", O="Hudson Exchange Group, LLC", L=Woodcliff Lake, S=New Jersey, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
5B78F4208F4D587B6FA9A6AF8EC8FD12

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:tJUE2avsDclFHEWUF43/MQFJQyJlaVjXw:tJv2avgcXk/4PMeZ7w7w

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8929

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file Setup.exe has been seen being distributed by the following 2 URLs.

Remove Setup.exe - Powered by Reason Core Security