Setup.exe

OL2, Inc.

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from games.onlive.com and multiple other hosts.
Publisher:
OnLive  (signed by OL2, Inc.)

Product:
OnLive

Version:
1.1.0.130599

MD5:
18c68ac148d8a21adb578141a6457764

SHA-1:
cb18cc40b1e3a5166cd8b77aa0761987d0e3d8f9

SHA-256:
7b26d9ed816546cd873d4ab15a5bb5eab14b6a3fe005cf87d614ae082ec5e3ee

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/26/2024 1:13:10 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PC-Guard
7.1.1

Trend Micro House Call
Suspicious_GEN.F47V0320
7.2.85

File size:
6.2 MB (6,537,232 bytes)

Copyright:
Copyright © 2009-2015 OnLive, Inc.

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
3/17/2014 2:56:27 PM

Valid to:
3/17/2017 2:56:27 PM

Subject:
E=ssladmin@onlive.com, CN="OL2, Inc.", O="OL2, Inc.", L=Mountain View, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112127BDFA432EC1E594BDEFD6A01EBE32A7

File PE Metadata
Compilation timestamp:
12/5/2009 4:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:Dx9fVLXLtSN8Hfazn6eICJ5hxHl/xgWl9bqKN:JNSQaz6eI2pF/WWXq+

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Entropy:
7.9983

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file Setup.exe has been seen being distributed by the following 2 URLs.

Scan Setup.exe - Powered by Reason Core Security