setup.exe

CardRecoveryPro

LionSea Software co., ltd

The application setup.exe, “CardRecoveryPro Setup ” by LionSea Software co., ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
LionSea SoftWare   (signed by LionSea Software co., ltd)

Product:
CardRecoveryPro

Description:
CardRecoveryPro Setup

MD5:
f3e9dfad3bd81a2a971fb1907b7f1054

SHA-1:
e1a147522d36a8963676ebdfdf3ed32d0fb8bcbf

SHA-256:
d1365c58ac9ef01db6ce16ba09e7139606562c543399321e1304cefedca5d048

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:26:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.LionSeaSoftwarecoltd.F
14.2.7.12

File size:
2.5 MB (2,627,472 bytes)

Product version:
2.1.5

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/8/2012 1:00:00 AM

Valid to:
2/8/2013 12:59:59 AM

Subject:
CN="LionSea Software co., ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="LionSea Software co., ltd", L=beijing, S=beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C82730AFCB40651922D0DB016CEEFF7

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:Lu9N6wirXxh7qeRxpnqDtqB0BdojUoGFC0zwVi0YrqRBRJgL:sN6XrXxhDnpnetEiqVNXRqL

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file setup.exe has been seen being distributed by the following 5 URLs.

http://gsf-cf.softonic.com/e1a/147/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3352781&instance=softonic_en&type=PROGRAM&Expires=1464610320&Signature=DAgi3TbKsfrlDsVduV64pAlKnYd4BC8tYRD6zStqpIORCz2rny5t7BDW6w4E7wjSKGDHq45TkIopa3hr76ZfIRxrs7D0l9dD6Wd2xh5SiFzan0OoCjTYHKGAOBZm3uL1AWBSgZ2vBcnWUgJ6Hb~vrSlpaiRAUpJr51nxQsnVXsw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup.exe

Remove setup.exe - Powered by Reason Core Security