setup_3106-1016.exe

音乐FM安装程序

广西南宁市昇桔光在线信息技术有限公司

The application setup_3106-1016.exe by 广西南宁市昇桔光在线信息技术有限公司 has been detected as a potentially unwanted program by 14 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from down.yinyue.fm.
Publisher:
Sta  (signed by 广西南宁市昇桔光在线信息技术有限公司)

Product:
音乐FM安装程序

Version:
1.0.0.0

MD5:
fd3cb6f467acb884b4b470132db1f19d

SHA-1:
d252a099bec794792080630308497374228ce769

SHA-256:
67f1b12105acdb0f3d5e0eb0461ed09113478f6d31258117cb330b3c32c61875

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/28/2024 12:46:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
APPL/wuji.cldok
8.3.2.4

Bkav FE
W32.eHeur.Downloader
1.3.0.7400

Clam AntiVirus
Win.Trojan.12392734
0.98/21511

Dr.Web
Trojan.DownLoader9.59141
9.0.1.028

ESET NOD32
Win32/WuJi.K potentially unwanted (variant)
10.12804

G Data
Win32.Trojan.Agent.BB
16.1.25

IKARUS anti.virus
Win32.Malware
t3scan.1.9.5.0

McAfee
Artemis!FD3CB6F467AC
5600.6506

Rising Antivirus
PE:PUF.MusicFM-MD5-Flood!1.9F71 [F]
23.00.65.16126

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
9357

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
46202

Zillya! Antivirus
Adware.OutBrowse.Win32.81779
2.0.0.2591

File size:
3.6 MB (3,769,128 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (C) 2012

Original file name:
SetupApp.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, China)

Common path:
C:\users\{user}\downloads\new folder\samsung s4\tempchace\setup_3106-1016.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
6/21/2013 11:51:31 AM

Valid to:
6/23/2014 5:08:06 PM

Subject:
E=kvzy126@qq.com, CN=广西南宁市昇桔光在线信息技术有限公司, O=广西南宁市昇桔光在线信息技术有限公司, L=南宁市, S=广西壮族自治区, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
0B9B0DFF23DA39

File PE Metadata
Compilation timestamp:
9/12/2013 10:13:00 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:C+Ma87Zc2mwL+xi6i66SBdpdRKI2+ru6RyytZSwuKF1rKBP+QXe6YkhpuDWiK9Mw:WoCgi6l68dpdAByXhrOWQiLKiK9MhKGi

Entry address:
0x96C8

Entry point:
E8, 9C, 3C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 88, 53, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 80, 51, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 18, C3, 41, 00, 89, 0D, 14, C3, 41, 00, 89, 15, 10, C3, 41, 00, 89, 1D, 0C, C3, 41, 00, 89, 35, 08, C3, 41, 00, 89, 3D...
 
[+]

Entropy:
7.9359  (probably packed)

Code size:
79 KB (80,896 bytes)

The file setup_3106-1016.exe has been seen being distributed by the following URL.

Remove setup_3106-1016.exe - Powered by Reason Core Security