setup.exe

I. d. l. e . C. r. a. w. l. e. r

SADDLEBACK PROC LTD

Part of the GigaClicks Crawler, a bot which collects Internet usage data targeted toward advertising. The application setup.exe, “Setup Application” by SADDLEBACK PROC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from ic.id142.soft-cdn.com.
Publisher:
SADDLEBACK PROC LTD  (signed and verified)

Product:
I. d. l. e . C. r. a. w. l. e. r

Description:
Setup Application

Version:
98.0.0.445

MD5:
6e93bd3a5b816e629b0019a226794563

SHA-1:
d12ca913b7284c7151757066fd6866bfda545535

SHA-256:
f6677b00cefd56af982abf05f92e625be30c443c16bd9a0c3dfc3afc26b7deb3

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 12:02:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.GigaClicks (M)
16.12.7.8

File size:
1.6 MB (1,679,216 bytes)

Product version:
2.0.1.0

Copyright:
© SADDLEBACK PROC LTD

Trademarks:
I. d. l. e . C. r. a. w. l. e. r is a trademark of SADDLEBACK PROC LTD

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/7/2014 8:00:00 PM

Valid to:
8/8/2015 7:59:59 PM

Subject:
CN=SADDLEBACK PROC LTD, O=SADDLEBACK PROC LTD, STREET=BRUNEL HOUSE 340 FIRECREST COURT, L=WARRINGTON, S=CHESHIRE, PostalCode=WA1 1RG, C=GB

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5664702C59BAF910D81BCEB424F4946D

File PE Metadata
Compilation timestamp:
5/11/2014 4:03:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x322E

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 14, C7, 44, 24, 10, D8, A2, 40, 00, 89, 6C, 24, 1C, FF, 15, 34, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 81, 40, 00, 55, FF, 15, AC, 82, 40, 00, 6A, 08, A3, 58, 4F, 43, 00, E8, 9F, 2E, 00, 00, A3, A4, 4E, 43, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, B8, B1, 42, 00, FF, 15, 7C, 81, 40, 00, 68, C0, A2, 40, 00, 68, A0, 3E, 43, 00, E8, 0A, 2B, 00, 00, FF, 15, 38, 81, 40, 00, BB, 00, F0, 43, 00, 50, 53, E8, F8, 2A, 00, 00...
 
[+]

Entropy:
7.9774

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file setup.exe has been seen being distributed by the following URL.

http://ic.id142.soft-cdn.com/138.exe

Remove setup.exe - Powered by Reason Core Security