setupa.exe

White Sea Media

The application setupa.exe by White Sea Media has been detected as adware by 3 anti-malware scanners. This is a setup program which is used to install the application. This is a trojan Bot that uses IRC to communicate with a comand and control network. The Trojan drops other malicious software and opens a backdoor on the infected computer and will run automatically on each boot. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from shoppingsuggestion.com.
Publisher:
White Sea Media  (signed and verified)

MD5:
428b28b11ad4656f72b3965204ec8b98

SHA-1:
23beef02b91c3bc7cb2bdfe227b42b1ba9d316e9

SHA-256:
789b0571aac53c8f9d985d071e5f0d304a29ebe3d7c70e9fb1269d7d1eaeafb3

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Part of a backdoor IRC bot network.

Analysis date:
11/5/2024 11:36:08 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.BtcMine.221
9.0.1.0354

Reason Heuristics
PUP.Installer.WhiteSeaMedia.G
14.8.7.21

VIPRE Antivirus
Backdoor.Win32.Ircbot.gen
24278

File size:
1.2 MB (1,225,952 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setupa.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/7/2013 9:00:00 PM

Valid to:
7/8/2014 8:59:59 PM

Subject:
CN=White Sea Media, O=White Sea Media, STREET=4142 Mariner Blvd, L=Spring Hill, S=FL, PostalCode=34609, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1FB235ACA7565BA27ADC702B2BD05C7F

File PE Metadata
Compilation timestamp:
11/22/2013 7:42:59 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:4iQgoLrMdGevQU7XAxkc7xTRIzIWRJtq8AAE5uFiVRpwb2:4QOgG4LAxkeTRofZ+kFSX22

Entry address:
0x326000

Entry point:
83, EC, 04, 50, 53, E8, 01, 00, 00, 00, CC, 58, 89, C3, 40, 2D, 00, 30, 12, 00, 2D, 8F, 8E, 0A, 10, 05, 84, 8E, 0A, 10, 80, 3B, CC, 75, 19, C6, 03, 00, BB, 00, 10, 00, 00, 68, 0B, 9B, D3, 64, 68, 66, 60, 6C, 65, 53, 50, E8, 0A, 00, 00, 00, 83, C0, 00, 89, 44, 24, 08, 5B, 58, C3, 55, 89, E5, 50, 53, 51, 56, 8B, 75, 08, 8B, 4D, 0C, C1, E9, 02, 8B, 45, 10, 8B, 5D, 14, 85, C9, 74, 0A, 31, 06, 01, 1E, 83, C6, 04, 49, EB, F2, 5E, 59, 5B, 58, C9, C2, 10, 00, 13, 68, 3B, 31, D8, 1B, 9B, 10, A0, E6, 6F, 29, 98, 82...
 
[+]

Code size:
28.5 KB (29,184 bytes)

The file setupa.exe has been seen being distributed by the following URL.

Remove setupa.exe - Powered by Reason Core Security