Setup.exe

Code Techno

The file Setup.exe by Code Techno has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from freempr9.jrcaaa.com and multiple other hosts.
Publisher:
Code Techno  (signed and verified)

MD5:
56ad9961609d0e2cdecdbca240c2a3bc

SHA-1:
ce3e0af195a47743daf19e35505461234ad2cdcd

SHA-256:
35bf8d17c347ce7a73424dbcf469b59af0eb34831a46eda28da9c9b3c74543eb

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
11/25/2024 8:23:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Downware
2014.12.07

Avira AntiVirus
ADWARE/Adware.Gen
7.11.193.42

AVG
Generic
2015.0.3250

Clam AntiVirus
Win.Adware.Downloadadmin
0.98/21511

Dr.Web
Adware.Downware.2220
9.0.1.0359

ESET NOD32
Win32/DownloadAdmin (variant)
8.10836

Fortinet FortiGate
Riskware/DownloadAdmin
12/25/2014

G Data
Win32.Application.DownloadAdmin
14.12.24

IKARUS anti.virus
Trojan.Dropper
t3scan.1.8.5.0

Malwarebytes
PUP.Optional.DownloadAdmin
v2014.12.25.03

McAfee
Artemis!56AD9961609D
5600.6906

NANO AntiVirus
Riskware.Win32.Downware.djahkt
0.28.6.63850

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.CodeTechno.CC
14.12.25.3

Sophos
Generic PUA MO
4.98

VIPRE Antivirus
DownloadAdmin
35480

File size:
821.2 KB (840,936 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2014 1:00:00 AM

Valid to:
2/26/2017 12:59:59 AM

Subject:
CN=Code Techno, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Code Techno, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
57F2A4C1987266C5627CFFB542729A0B

File PE Metadata
Compilation timestamp:
7/15/2014 6:29:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:rxpJfslZtuaVd9lpmhwQbift489IVGD4xJFl6Xqb5Kbmkg8SU5:lp9sVuaVdvgVbmgGDijyikg54

Entry address:
0x3345

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2E, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1F, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0D, 24, 00, 00...
 
[+]

Entropy:
7.4890

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file Setup.exe has been seen being distributed by the following 3 URLs.

Remove Setup.exe - Powered by Reason Core Security