setup.exe

Sid Meier's Civilization 5

tapochek.net

The application setup.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from volafile.io.
Publisher:
tapochek.net

Product:
Sid Meier's Civilization 5

Version:
1.00

MD5:
9cac362f0c8a3c7118b9b597880370cb

SHA-1:
b2c269e993457e3aa1495ceaf99127c3cae19884

SHA-256:
8c94cdc5704820a04d99216539582814b1fbd0cc8e7bf1eafa79803e02ab6e05

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/28/2024 4:55:42 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
v2016.05.11.05

Qihoo 360 Security
HEUR/QVM03.0.0000.Malware.Gen
1.0.0.1120

Reason Heuristics
PUP.InstallCore (M)
16.5.12.17

File size:
1.1 MB (1,200,128 bytes)

Product version:
1.00

Copyright:
R.G. Mechanics, Panky

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
5/11/2016 9:25:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:/azxlkE4wSXOmI3qlrbfQSEC3DPzhPhZH29B8Lbbbbbbbb:isE2XObqlXfQ+PzvZU

Entry address:
0x1214

Entry point:
68, E8, DA, 51, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, B8, ED, 89, 2B, 58, B8, AD, 45, 98, A0, AB, 7D, 8E, 3D, B7, AC, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 88, 72, 31, 03, 76, 62, 34, 70, 72, 6F, 6A, 65, 63, 74, 56, 62, 00, 08, 41, 00, 00, 00, 00, 00, FF, CC, 31, 00, 03, 63, F2, 99, 32, F5, A0, CD, 44, 99, 0A, E9, A2, 01, D2, 1A, 09, F6, 2E, FF, 6F, B4, E8, 49, 48, 9D, B3, EE, B8, 57, D5, 21, EF, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
1.1 MB (1,187,840 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security