setup_118.exe

速浪输入法

Beijing Yu Jin Cheng Technology Co., Ltd.

The application setup_118.exe by Beijing Yu Jin Cheng Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from srfdown.sulang.com.
Publisher:

Product:
速浪输入法

Version:
1.0.0.1

MD5:
52ef626635547eebea109da8e496e720

SHA-1:
a369ea151d51ee26c1cc62f4aedf47dc6aa202f9

SHA-256:
739ae3479997ff78161b894b550fe0e8b548e4236833d8f7cdaae919fc8472da

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 10:37:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BeijingY.Installer (M)
16.3.12.0

File size:
6.7 MB (7,010,272 bytes)

Product version:
1.0.0.1

Copyright:
北京御金诚科技有限公司

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\setup_118.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
8/19/2015 1:47:31 PM

Valid to:
12/30/2016 1:47:31 PM

Subject:
CN="Beijing Yu Jin Cheng Technology Co., Ltd.", O="Beijing Yu Jin Cheng Technology Co., Ltd.", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
5101E5E4803BA58F107087F0934A122F

File PE Metadata
Compilation timestamp:
1/2/2015 11:45:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:EdqemXS7S3hV93Vag/IAjpBqM1IqPNvIyHlZH4lvDkjFcywA6bR0B7Dvhj:pV3NVag/IA1EM/9FZHaQjDkbR6bR

Entry address:
0x3783

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 00, 8A, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, D8, 88, 44, 00, E8, 90, 27, 00, 00, 53, 68, 60, 01, 00, 00, A3, E0, 87, 44, 00, 8D, 44, 24, 38, 50, 53, 68, 93, 8A, 40, 00, FF, 15, 58, 81, 40, 00, 68, 88, 8A, 40, 00, 68, E0, 47, 44, 00, E8, D0, 24, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, 00, 10, 47, 00, 57, E8, BE, 24, 00, 00...
 
[+]

Entropy:
7.9988

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file setup_118.exe has been seen being distributed by the following URL.

Remove setup_118.exe - Powered by Reason Core Security