setup.exe

Installer

VerifiedInstallation

The application setup.exe by VerifiedInstallation has been detected as adware by 24 anti-malware scanners. The file has been seen being downloaded from zipdownloader.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
VerifiedInstallation  (signed and verified)

Product:
Installer

Version:
1.0.0.1

MD5:
00deaeabf3e7c8b080edc5c7c9c11a23

SHA-1:
b066a2361cffab324944dcaadc58a411f879be78

SHA-256:
c15dc2c2104d4802d39dcb979d973931184739ff44b1122ad099c70dd69adbc3

Scanner detections:
24 / 68

Status:
Adware

Analysis date:
11/26/2024 11:52:54 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.189304
5621779

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Generic
2015.05.17

Avira AntiVirus
W32/Neshta.a
7.11.30.172

avast!
Win32:Evo-gen [Susp]
150525-2

AVG
AdGazelle
2016.0.3091

Bitdefender
Gen:Variant.Adware.Strictor.86912
1.0.20.760

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.11074
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.189304
10.0.0.5366

ESET NOD32
Win32/AdGazelle.J potentially unwanted application
7.0.302.0

F-Prot
W32/S-6897f6c9
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
5.14.151

G Data
Gen:Variant.Adware.Strictor.86912
15.6.25

IKARUS anti.virus
PUA.AdGazelle
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15794

Malwarebytes
PUP.Optional.Downware
v2015.06.01.11

MicroWorld eScan
Gen:Variant.Adware.Strictor.86912
16.0.0.456

NANO AntiVirus
Riskware.Win32.Downware.drcqse
0.30.24.1357

Norman
Gen:Variant.Adware.Graftor.189304
03.12.2014 13:20:04

Panda Antivirus
Trj/Genetic.gen
15.06.01.11

Qihoo 360 Security
Win32/Virus.Adware.c16
1.0.0.1015

Reason Heuristics
PUP.AdGazelle.Installer
15.6.1.19

VIPRE Antivirus
Threat.5063330
39676

File size:
275.6 KB (282,176 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/3/2015 3:42:42 PM

Valid to:
3/3/2016 3:42:42 PM

Subject:
CN=VerifiedInstallation, O=VerifiedInstallation, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00AD549677C65B0FD8

File PE Metadata
Compilation timestamp:
6/1/2015 3:10:04 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:lHW+NAJ02GCZU8cW1mGVjhjCcpCAyjMj+OMQCfAg0Fu0Ag0Fu8xMX5c5vd:lHtA22rZqW/V1dpCjjMjPeAO0AOhJcD

Entry address:
0xFB43

Entry point:
E8, 90, AC, 00, 00, E9, 8B, FE, FF, FF, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, E8, C2, 43, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A8, 43, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, E8, C2, 43, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03...
 
[+]

Entropy:
6.2462

Code size:
160.5 KB (164,352 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security