setup.exe

bundlebeez ltd.

The application setup.exe by bundlebeez ltd has been detected as a potentially unwanted program by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from d3.peackapp.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
Installer  (signed by bundlebeez ltd.)

Product:
Installer

Version:
1.48.0.0

MD5:
5790880563761215d2f0ee773478529b

SHA-1:
c792c93a3edb5fb4238fe988af99299e3b1a1680

SHA-256:
520d6a520a612518fd2b44851c7b26f42a80c49f7a6219467b169050f19b9f31

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
2/25/2025 11:54:33 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/TrueDown.glo
8.3.1.6

avast!
Win32:Evo-gen [Susp]
2014.9-160207

AVG
Adware Generic6
2017.0.2840

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.TrueDown.GIIG
22250

ESET NOD32
Win32/Adware.TrueDownloader.A application
10.7.0.302.0

IKARUS anti.virus
PUA.TrueDownloader
t3scan.1.9.2.0

K7 AntiVirus
Adware
13.204.16045

Reason Heuristics
PUP.bundlebeez.Installer (M)
16.2.7.20

VIPRE Antivirus
Threat.5065747
40552

File size:
407.6 KB (417,392 bytes)

Product version:
1.48.0.0

Copyright:
Copyright (C) 2014

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/8/2014 7:00:00 PM

Valid to:
12/9/2015 6:59:59 PM

Subject:
CN=bundlebeez ltd., OU=bundlebeez, O=bundlebeez ltd., STREET=1 habarzel st., L=tel aviv, S=israel, PostalCode=69710, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C76FF2C3632486922817A7EBE894CE9E

File PE Metadata
Compilation timestamp:
1/19/2015 9:24:11 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:KnDD9OqE4tqfqqzdLfqHSOGrqRyuZsRCYyL40ZHjDdiUGv:oDD994zBfA/zYuSRCYchSv

Entry address:
0x118D70

Entry point:
60, BE, 00, 70, 4C, 00, 8D, BE, 00, A0, F3, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8931

Packer / compiler:
UPX 2.90LZMA

Code size:
328 KB (335,872 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security