setup.exe

The application setup.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from f0p4dmfxm.d26vzqu7.com and multiple other hosts.
MD5:
0e11690931b168972de9736e39055bcb

SHA-1:
fbeb29c9304f1c36fa8d82ad604f3bfe7f6fb055

SHA-256:
54883398461ef5c6e03a404f07af45517c52d6ca4ef2eab5a23d84404047ae76

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
11/26/2024 5:55:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.SoftPulse.2
838

AegisLab AV Signature
AdWare.W32.Agent
2.1.4+

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.10.19

Avira AntiVirus
APPL/Softpulse.Gen8
7.11.179.120

avast!
Win32:SoftPulse-AK [PUP]
141003-0

AVG
Generic
2015.0.3316

Bitdefender
Gen:Variant.Application.Bundler.SoftPulse.2
1.0.20.1460

Clam AntiVirus
Win.Trojan.Softpulse-57
0.98/21411

Dr.Web
Trojan.DownLoader11.36367
9.0.1.05190

ESET NOD32
Win32/SoftPulse (variant)
8.10584

F-Secure
Gen:Variant.Application.Bundler
11.2014-19-10_1

G Data
Gen:Variant.Application.Bundler.SoftPulse
14.10.24

IKARUS anti.virus
Trojan.Win32.Buzus
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.184.13727

Kaspersky
Trojan.Win32.Buzus
15.0.0.494

Malwarebytes
PUP.Optional.DomaIQ
v2014.10.19.09

McAfee
SoftPulse
5600.6972

MicroWorld eScan
Gen:Variant.Application.Bundler.SoftPulse.2
15.0.0.876

NANO AntiVirus
Trojan.Win32.LMN.dgkmmt
0.28.2.62671

nProtect
Trojan/W32.Buzus.1623056
14.10.17.01

Reason Heuristics
Threat.Win.Reputation.IMP
14.10.19.21

Sophos
SoftPulse
4.98

Vba32 AntiVirus
BScope.Adware.Softpulse
3.12.26.3

VIPRE Antivirus
Threat.4150696
33706

Zillya! Antivirus
Adware.Agent.Win32.14266
2.0.0.1959

File size:
1.3 MB (1,391,086 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
10/9/2014 12:11:04 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:+zD5urNhRWx2Mk4JJQByw7Imlq3g495S0PwbphrpgXXOZuv/rTWeR4:m6/ye0PIphrp9Zuvjq7

Entry address:
0x6978

Entry point:
E8, DB, 40, 00, 00, E9, 7F, FE, FF, FF, E9, B4, 26, 00, 00, FF, 35, 20, CD, 4A, 00, FF, 15, DC, 50, 41, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, D2, 38, 00, 00, 6A, 01, 6A, 00, E8, 7C, 47, 00, 00, 83, C4, 0C, E9, 93, 47, 00, 00, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, D3, 47, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, A6, 2B, 00, 00, 59, 85, C0, 74, E6, C9, C3, 6A, 01, 8D, 45, FC, 50, 8D, 4D, F0, C7, 45, FC, C4, 30, 4A, 00, E8, 4D, 2F, 00, 00, 68, 1C, 94, 4A, 00, 8D, 45, F0, 50, C7, 45, F0, BC, 30...
 
[+]

Code size:
76.5 KB (78,336 bytes)

The file setup.exe has been seen being distributed by the following 3 URLs.

Remove setup.exe - Powered by Reason Core Security