setup.exe

Installer

Stepitapp LLC

The application setup.exe by Stepitapp has been detected as adware by 8 anti-malware scanners. The file has been seen being downloaded from www.mydownloadhome.com and multiple other hosts. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Stepitapp LLC  (signed and verified)

Product:
Installer

Version:
1.0.0.0

MD5:
bddcd8810ee17cb375f8c9650563ce0e

SHA-1:
bd430c3d62d820269a7f85ec73181db002e158e7

SHA-256:
e1606f3281d5293024fe79aa2e371def83b3f2a5be7674650b26307edef07b52

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
11/26/2024 11:49:38 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Hacktool.Win32.Downloader
4.0.3.1557

herdProtect (fuzzy)
2015.8.5.3

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.2080

Panda Antivirus
Trj/Chgt.E
15.05.07.01

Qihoo 360 Security
Malware.Radar03.Gen
1.0.0.1015

Reason Heuristics
Threat.Installer.Stepitapp
15.5.6.21

Trend Micro House Call
Suspicious_GEN.F47V0916
7.2.127

VIPRE Antivirus
Conduit
33182

File size:
402.4 KB (412,080 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2013

Original file name:
FinalInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/10/2013 4:00:00 PM

Valid to:
12/11/2014 3:59:59 PM

Subject:
CN=Stepitapp LLC, O=Stepitapp LLC, POBox=1252, STREET=9 W. 31st Street, L=Bayonne, S=New Jersey, PostalCode=07002, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EA7DEF51F4F715C2C81433CCD6B15766

File PE Metadata
Compilation timestamp:
9/8/2014 7:19:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:NlTZuR44xlfCtibqI59PpOPf201/z7pumJI9ftRm7X75:NlTQR4BtibqI59Pk2cb7pumJ0ftRA5

Entry address:
0x62A5E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1785

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
387 KB (396,288 bytes)

The file setup.exe has been seen being distributed by the following 3 URLs.

http://www.mydownloadhome.com/.../2?pub_id=88&sub_id=LrEDIw6Xhuukc_6zQmvrXkVj-vriI9YtvjhG7rg-rmKJ9I77HqLGP9LHoyFqnRWI9tzHjnIDPQejh5HwvWOJoRLepGnEZdbXVepNZHzTCbDt9S_yV2YdyK2cNkXgdkDemUun3Z97BgnkUHlaeIHJawHHNzg2_dMk4zcOwdWow9okvUjnMpFSof2CE4DJ9yTNGUwukai-oy40xBfEesAQEpuf1SqCMA1jR_TudT7LSZmhMfzPYwZ8j0DeWh7P67ISMLjY88uzMmJn4BuRjCJ_ifgCl-XJUv3jgBqOGjM00A9PE-IeAWg_b5STJ6rSv2B0Rf8EVFgYX5qCSdfiIgxywfY7u0plKhwJFq1DRDfiAi4j5WdnP_Si17ymNySeuzntia1UITpMLdkDTt-JbPsrYRDjW26m_HrvHtJbtPzKxCfWIgHtAC21RJ11Lnb3i6B8XWceeNwXjrQlKWk

http://www.mydownloadhome.com/.../2?pub_id=88&sub_id=mR2xjGca3Ygi7X3XO6WBSDUYcHk2h5wCdgPuWdx2QYfOo0NpU0d48MvBVOLQASU9I8ClSQ1O6-JAUYut_QNhOXxWMEV1eOU8GsSlrOpbpqe1WHjrTPt4zxoaJaY66WaPvz2cFIK4G701Na3rV19p2aIB2eu9i-jwlfJcoFWtgTYORXft8nQMW8cSVaK6ZAxPtOPBFdpeH_EzSIMgE7vRDjv2geaawTPstMz0GEKSNC6mizFIxhOJS2HaFi0-32XH3UJ6G5sHIsew2wi83eNoLHIgiVX42QGfUPNwWUTeALRlFk14jjZDkyaEZGupOePlEK2uwU53LdIOddolh1RtcYXD7BiGzHmjdZnET7PO-a_v7rFFKM03d-nloVLNHgrLYPHEjw60rkQWbQoOfWomsQYXXXj1745f8NYjPmjFf1XQpCQcPNB50hbjYcjgnKiwVWJhdx0F3wFhEA

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove setup.exe - Powered by Reason Core Security