setup.exe

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download1130.mediafire.com and multiple other hosts.
MD5:
81e69b29c4c09391a12b665e7661f48e

SHA-1:
b103b694d12544c9db444badd9e2263d219698b1

SHA-256:
81e45c1e6d6a718624159e116e6daa8c1547f39bef7f56163303e7eca8abfae1

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/2/2024 3:33:33 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.Spy
2.1.4+

Bkav FE
W32.Clodfc1.Trojan
1.3.0.4959

Norman
Suspicious_Gen2.NSCMQ
11.20140501

Rising Antivirus
PE:Trojan.Win32.Generic.128780F6!310870262
23.00.65.14429

File size:
3.9 MB (4,093,845 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\vst plugins\installations\dada.life.sausage.fattener.vst.v1.0.x86.x64-assign\setup.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:QhVVJqioKMFh1qKsbZcMgsGwNmlCNE4CJgcMyfQP/4:QhV1pMzHQCMFGImHgcM54

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following 50 URLs.

http://download1130.mediafire.com/hv6hwxjv5bgg/.../setup.exe

http://download1130.mediafire.com/g1km89lwwvcg/.../setup.exe

http://download1623.mediafire.com/96jgd3ec2gpg/.../Sausage Fattener Win.exe

http://download1617.mediafire.com/zenqa6vneohg/.../Sausage Fattener Win.exe

http://download2223.mediafire.com/nobef81s9pgg/.../Sausage Fattener Win.exe

http://download2223.mediafire.com/fd30rbf3dbug/.../setup.exe

http://download1409.mediafire.com/usgn1an1nnmg/.../setup.exe

http://download1088.mediafire.com/vcrtom7ax6vg/.../setup.exe

http://download1617.mediafire.com/c2531c7jg8yg/.../setup.exe

http://download1617.mediafire.com/f231w020bcug/.../setup.exe

http://ttb.youfilejd.com/download/request/.../0uEGsUPH?__tc=1464284882.93&lpsl=356e9c79ed8d029422196003cc658302&expire=1464371274&PubID=ht_ww_mix&clickid=PLl1mtJzpFjh69uqTOdZbMh3KOMbFsSploxz4zqTJRJuwhHs22HOJu5dSoexCeydg_x-C9DaP4k1B5gLfiKNFKj5GOmxOtVvI8GybeIEY4OPOCJj9HBOjVTZehQa6Fl36QTLl2YQOvTMYcLUtR9TOWMAaKc1t0o219S59F8Ax0V1zAplLNpbzFwKotrpIURMJOohPs96OsqHtaNKSddZIBFnEnzaRdkb149tYtH28VOO9Vzl6N7VEYe_MZ0JhAhQ&slp=www.newfileord.com&fileName=Setup

http://download1736.mediafire.com/5uy3yfw8n5rg/.../Sausage Fattener Win.exe

http://download1736.mediafire.com/bva8n2dkik2g/.../Sausage Fattener Win.exe

http://download1088.mediafire.com/c5md8u305seg/.../Sausage Fattener Win.exe

http://download1736.mediafire.com/ojguystuu4tg/.../setup.exe

http://download1736.mediafire.com/24ne1fb3mtvg/.../setup.exe

http://download1088.mediafire.com/ry23wh2kxirg/.../setup.exe

http://download1130.mediafire.com/zcerruhdbprg/.../setup.exe

http://download1736.mediafire.com/5w0cc7q0o77g/.../setup.exe

http://download1088.mediafire.com/s1stz7ka31zg/.../setup.exe

http://download1736.mediafire.com/uv8cfgbs3vng/.../setup.exe

http://download960.mediafire.com/1ewzjkghgnxg/.../Sausage Fattener Win.exe

http://download1736.mediafire.com/sngxv9dgdugg/.../Sausage Fattener Win.exe

http://download1088.mediafire.com/vxdrui55gajg/.../setup.exe

http://download2223.mediafire.com/d773lmb2058g/.../setup.exe

http://ttb.lpcloudsvr302.com/download/request/.../ZL36bgPO?__tc=1389372204.438&tgu_src_lp_domain=www.allsoftdll.com&ClickID=15240267821389372191&PubID=151018

http://ttb.lpmxp2161.com/download/request/.../xb9onqTr?__tc=1410401663.425&lpsl=0dc05c063a6706b7ad23e399b82fbb21&expire=1410488064&PubID=125524&tgu_src_lp_domain=www.softddlupdate.com&ClickID=31872335281410401663&fileName=Setup

http://www73.zippyshare.com/d/37879023/.../Sausage Fattener Win.exe

http://download1736.mediafire.com/rxub55g257og/.../setup.exe

http://download1213.mediafire.com/8n77k762avxg/.../Sausage Fattener Win.exe

Latest 30 of 63 download URLs

Scan setup.exe - Powered by Reason Core Security