setup.exe

Small Island Development

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Small Island Development has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from gp387a.sazzip.com.
Publisher:
Small Island Development  (signed and verified)

MD5:
df2592637a571e9ac9f3b6d7d77d07ea

SHA-1:
b7953f9e8eb386123a77dbc3ff70a11b3b578db1

SHA-256:
d6b747c2172352bc7008aeb352bec9efcf62f615f717b28c3a95f1c32615c188

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
11/23/2024 9:45:07 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.PullUpdate
7.1.1

AhnLab V3 Security
PUP/Win32.MovieWizard
2015.03.28

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

AVG
Generic_r
2016.0.3157

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15328

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Yontoo.59
9.0.1.087

ESET NOD32
MSIL/Adware.PullUpdate
9.11388

K7 AntiVirus
Adware
13.202.15407

Kaspersky
not-a-virus:AdWare.MSIL.PullUpdate
14.0.0.2278

Malwarebytes
PUP.Optional.MovieWizard.A
v2015.03.28.09

Panda Antivirus
Adware/TVWizard
15.03.28.09

Quick Heal
PUA.MSJDGBTIR.OD6
3.15.14.00

Reason Heuristics
PUP.Installer.Injekt
15.3.28.9

Vba32 AntiVirus
AdWare.MSIL.PullUpdate
3.12.26.3

VIPRE Antivirus
Injekt
38834

File size:
4.4 MB (4,575,696 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/23/2014 7:00:00 PM

Valid to:
2/22/2016 6:59:59 PM

Subject:
CN=Small Island Development, O=Small Island Development, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2ACB4CDCE993E485342ABFA2BCA95A17

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:GBTjDE9KyXrQAcwMwW6T3C6GQ/95qe5MSDfsca7InARjDE9KT5:qbEYO1MjAy6GQF5qaMS7ba7nJEYd

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9839

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security