setup_magic_ct.exe

3400_pjr_luckysearches

Fuyuan Zhou

The application setup_magic_ct.exe by Fuyuan Zhou has been detected as adware by 12 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d3kj6o4rxau601.cloudfront.net.
Publisher:
768  (signed by Fuyuan Zhou)

Product:
3400_pjr_luckysearches

Description:
768

Version:
6,3,7601,2068

MD5:
e032e979e64f6bedec9df62782da12aa

SHA-1:
872ef1fb5e7309ca7d120f14c34f470b9f5dfafb

SHA-256:
dc06de8ad6a8bd6e1b3cef82da1586c4d380dce6d90c6f173c59acd0818caf3a

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
4/17/2025 1:26:48 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Baidu Antivirus
Adware.Win32.ELEX
4.0.3.15331

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Mutabaha.359
9.0.1.0114

ESET NOD32
Win32/ELEX.CE potentially unwanted (variant)
9.11597

herdProtect (fuzzy)
2015.7.5.2

K7 AntiVirus
Adware
13.203.15849

Malwarebytes
PUP.Optional.OurSeaching.A
v2015.03.31.05

Quick Heal
PUA.MSJDGBTIR.OD6
4.15.14.00

Reason Heuristics
PUP.Installer.FuyuanZhou
15.3.31.5

Sophos
PUA 'Elex' (of type Adware)
5.14

VIPRE Antivirus
Threat.4726263
38552

File size:
473.6 KB (484,960 bytes)

Product version:
6,3,7601,2068

Copyright:
mysl

Original file name:
768

File type:
Executable application (Win32 EXE)

Language:
English (Storbritannien)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup_magic_ct.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/15/2015 1:00:00 AM

Valid to:
1/20/2016 1:00:00 PM

Subject:
CN=Fuyuan Zhou, O=Fuyuan Zhou, L=Jilin, S=Jilin, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08CA606335C89594E0B8D9706948A708

File PE Metadata
Compilation timestamp:
3/27/2015 11:00:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:hICUcYNzj0jO2WMux0Y7XZir3RYA2vfPW17aTBFZMf1sJJqmt:P2/fXC2Jir3Klvf47aTfZMf9mt

Entry address:
0x1F7DC

Entry point:
E8, 94, 6F, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, B4, BB, 46, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, A8, 80, 46, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, B4, BB, 46, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85...
 
[+]

Code size:
335.5 KB (343,552 bytes)

The file setup_magic_ct.exe has been seen being distributed by the following URL.

Remove setup_magic_ct.exe - Powered by Reason Core Security