Setup.exe

Hosa

Dimicina

The file Setup.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Dimicina

Product:
Hosa

Description:
pen hapetat

Version:
7.5.98.6679

MD5:
e03c4a7265adf80ed3109f221a1a0792

SHA-1:
fc893861d34e6828d20a005cf44cd9b6b3e63f3c

SHA-256:
66b8b8780d6feaba06dd31788e3254d2660495346a760b6b4e6312f2f2fa8988

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/8/2024 5:48:32 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.AEI.gen potentially unwanted application
8.0.319.0

Reason Heuristics
PUP.InstallCore (M)
16.4.15.18

File size:
495.2 KB (507,084 bytes)

Copyright:
Nimic

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
12/27/2015 5:38:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:gl9xlV7tODCF2sNH4YelCKhCXIqozva65zd5WyGMp:glzH7R5NH4YelWIwM

Entry address:
0x310D

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 1C, C7, 44, 24, 14, 88, 91, 40, 00, 33, F6, C6, 44, 24, 18, 20, FF, 15, B4, 70, 40, 00, FF, 15, B0, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, E4, 2D, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, 68, 7C, 91, 40, 00, E8, 65, 2D, 00, 00, 68, 74, 91, 40, 00, E8, 5B, 2D, 00, 00, 68, 68, 91, 40, 00, E8, 51, 2D, 00, 00, 6A, 0D, E8, B4, 2D, 00, 00, 6A, 0B, E8, AD, 2D, 00, 00, A3, 44, EC, 42, 00, FF, 15, 34, 70, 40, 00, 53, FF...
 
[+]

Entropy:
7.9696

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file Setup.exe has been seen being distributed by the following URL.

Remove Setup.exe - Powered by Reason Core Security