z-zipsetup.exe

Lenasepuc

Colifile SLU

The application z-zipsetup.exe, “Lenasepuc Setup ” by Colifile SLU has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.headbundlesfarm.com and multiple other hosts.
Publisher:
Kecu   (signed by Colifile SLU)

Product:
Lenasepuc

Description:
Lenasepuc Setup

Version:
1.6.2.0

MD5:
acb5b979fc576cf95323366c398123d8

SHA-1:
57508554cae26bd36524147aff0c5a94eb09d9e9

SHA-256:
063e2b62a2b8d9a3de882ef3638133114d545070d9151dd604b9ad1d5f1650e8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 11:37:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Colifile.Installer (M)
16.4.29.18

File size:
940 KB (962,520 bytes)

Product version:
5.2

Copyright:
File

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\z-zipsetup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
11/19/2015 7:00:00 AM

Valid to:
11/19/2016 6:59:59 AM

Subject:
CN=Colifile SLU, O=Colifile SLU, L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1D8228BD3D6A0EADA24B1453F4593406

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:MQPvETEbn364mHWrF0FEc75lD0Gl2poCC3w:MoPnq4mHWZc1lD0GjCCg

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9380

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file z-zipsetup.exe has been seen being distributed by the following 50 URLs.

http://www.headbundlesfarm.com/WVl6OTRQVWtsTWtaeFNVVlFVbWxKUVd4YWJIVnBValZYYkdKRGJGQk9NekJ2VTFCdU4zaG1SM0pzYkdkR09ISWxNa1p2SlRORUptTTlabVIyUzJveFVsRWxNa1ppU0ZjM2NHeDRiWFppSlRKR1MxWldXbTFRUkZOM2NUZzBla2syUkdrMEpUSkdWelpMU1ZBbE1rWjJiVGc0YXpseWNqRmhUVXRTUzJ4RGVGcGlhMWxESlRKR1RsQjFhbWRXZEdWNVJuSndiMVJIVTJFemFuRnFiM05NYUhweVdrNURWRFp6V0V4bVJFZEtkVVp4V1dwNVVsVm5iWE16U1ZWMlIwMW5TemhpSm1SdmQyNXNiMkZrUVhNOVdpMWFhWEJUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1prTkhKcWFqWndaakJqWVdwM0xtTnNiM1ZrWm5KdmJuUXVibVYwSlRKR1dpMWFhWEJUWlhSMWNDNWxlR1U9

http://www.headbundlesfarm.com/WVl6OTRQVFJ5Y0dSaE1FRm1ZVTFWZUdkUlMwSXpkWFpJVkRkNWRWTnFKVEpDTUhwUmFITnpKVEpDVVdwb1IyZzRUR2hCSlRORUptTTlXaVV5UWxReVYxcHBSVVVsTWtKTk1XZEVlWGhITlhkWWVqWmtRMFp0WkdKc2RGSnhjRE5GTTB0eGRUZDZUbXd3TlVaSk9VMWtPVFY0VTA4bE1rSjFRa1pHVmt3NWJVVlpNV2hRYVZZMkpUSkNTVFZpUlhabVNtRmhaSE5wTTNaNE1UZGpiMnh2VWxWSGRISTJXa3BRTmpWSGNqQTBSWFJRV0RWQ1lVaFVSRUZOZUZablVXVkRkaVprYjNkdWJHOWhaRUZ6UFZvdFdtbHdVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdaRFJ5YW1vMmNHWXdZMkZxZHk1amJHOTFaR1p5YjI1MExtNWxkQ1V5UmxvdFdtbHdVMlYwZFhBdVpYaGw=

http://www.headbundlesfarm.com/WVl6OTRQVFp1TkVwQ0pUSkNjRU5EVFdrMU1YUkZjVVkzVGxSclRHaFpjekppZUZNMGMyOXZPV2RqWVdJemNVdzNWU1V6UkNaalBVVXhRVTVUWmxBMWFXdHRkVUZwV1ZoaWNYRmxjRXBPY0VoT1RUUTBObHBTUzJaS1dYVTVZWFp4Ulc5SWFWVlBiVEJqY1U5MlpFcE9aWFZxV2tSWldXUjNkMEZPVW1sRmRFazJXVlYxVldsc2JrMW9ZemgxYkRZMFpuRkZhVmxMVlRkdVpVWktkSHB1WlZCWVpIVnRjazFsTjNJNE0xZ3dVMko0Wkc1SVUxWlJKbVJ2ZDI1c2IyRmtRWE05V2kxYWFYQlRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWmtOSEpxYWpad1pqQmpZV3AzTG1Oc2IzVmtabkp2Ym5RdWJtVjBKVEpHV2kxYWFYQlRaWFIxY0M1bGVHVT0=

http://www.headbundlesfarm.com/WVl6OTRQVUlsTWtKU2JtRnFNWE5yTW5SUWVqSmFOaVV5UWxGT1lYWmplR2hoYW5kTk4xQTBjbkJJTjFKMkpUSkNNMmhuZVRnbE0wUW1ZejB4WWtwVWFUZzBZVWRCWkZweFVGRjRRWEJrYW1WS2NVWm5WR1pyUjI1alpXTndPREJQT1RSc2RrTk1hVWw1V1VnNU1VbFVNamt3Y0V0emNqbHdiV05SZVdaVlZXNTRNak00TlVveFZqbEtTVlpZVVhSd1dFZHBTVkoxSlRKQ2NEQnpSMkUyWVZKTmVuWjRWVGhhZDFwallUQkxTVXgzTjFwaFJXNWhOR1p4VUdWd0ptUnZkMjVzYjJGa1FYTTlXaTFhYVhCVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaa05ISnFhalp3WmpCallXcDNMbU5zYjNWa1puSnZiblF1Ym1WMEpUSkdXaTFhYVhCVFpYUjFjQzVsZUdVPQ==

http://www.headbundlesfarm.com/WVl6OTRQVVZEYVZvNFYwOVNkMFZGTVdRMWNtZElWVGRTYjJ4aVYwZHJjRzlIVldaMWJEWjFVbnBpTVhoR2JqUWxNMFFtWXoxdVVscFFhR28xWjJKMkpUSkdWVEU0TnpKdU5HdHdjakZGUkdkMFFtRldPRmh6ZG1wVVZraDBaRkpCV0hCeWRESXdNVVZwVkRGNGVFRlNUa2hqT1ZnNU5XaGlhalp6U0dNNWNHRldSRnB0U2xwbWJEWWxNa0o1V2pWdU1IVmpkamhhVmtoWFZFNHlaM2xXWmpsb2VEaHlRM1ZYU0U1T01TVXlRaVV5Um1aTmVtNDRTbmNsTWtJbE1rWlRRaVprYjNkdWJHOWhaRUZ6UFZvdFdtbHdVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdaRFJ5YW1vMmNHWXdZMkZxZHk1amJHOTFaR1p5YjI1MExtNWxkQ1V5UmxvdFdtbHdVMlYwZFhBdVpYaGw=

http://www.headbundlesfarm.com/WVl6OTRQWGRwYUZONmNqTkhkMUJXVnpCSk9FNXNkRkZRTlRKTFZDVXlRblk0T0c5M09IVnFVbnBZVUdoV01URllheVV6UkNaalBVWTRlbFJFUW5WVFRUWlZXVlJFZDNoelRWQlVTM0lsTWtadFJrSlBRakY0U1NVeVFtNVdUekZWT0dWT1RWazNaSHBOYVhSR1prWkJXVVptY1ZVMFRtaFlSRlExU0VvMFYyNVJSVkpDYVV4RU1uaFJUbFZGVXpKUlZEbGxNV2ROU1RneU5tVkpjSEJaVVRRd05XOTNUSEFsTWtKSWEwRnFObm96YkZwM2VUUklhM1kzVTFZbE1rSW1aRzkzYm14dllXUkJjejFhTFZwcGNGTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtUTBjbXBxTm5CbU1HTmhhbmN1WTJ4dmRXUm1jbTl1ZEM1dVpYUWxNa1phTFZwcGNGTmxkSFZ3TG1WNFpRPT0=

http://www.headbundlesfarm.com/WVl6OTRQVXRrVDFWb1N6Um1Ra3hrWmlVeVFubEVkWEJHZVZOMFVtMW1SRlpzZWtKWlkzZDFZbXRxYmxoSWRDVXlSak5KSlRORUptTTlRazAxYW1VMmQxZFZZMnBIYlZsdlRuZEVaMjFSSlRKR2IybHdPRWdsTWtaNk16RnBTemxJUVRkWVIybFNPR1ZJWVVSNU5WQjZkVTlWYzNGQlRrc2xNa0p5Y2pVemRtSkpkVVZvTjNOSFdWTkhlbE4yVUUxVVRXNXpXakIzYW1VMFFYTWxNa1pCUTJ4Q1FUY3lVVGhRTjFoMWQwMVZjQ1V5UmxGb1dFUWxNa1o2V0dKUGJFZExNR2RYYUc0bVpHOTNibXh2WVdSQmN6MWFMVnBwY0ZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1RMGNtcHFObkJtTUdOaGFuY3VZMnh2ZFdSbWNtOXVkQzV1WlhRbE1rWmFMVnBwY0ZObGRIVndMbVY0WlE9PQ==

http://www.headbundlesfarm.com/WVl6OTRQVVpRWlRFeVpVTXliSFpVWVROWGJEZEhZalZUVVhscmEydDBWV1JRWjFOeE9WUlZNVGxCYURZd1Mwa2xNMFFtWXoxTFQwZEVWV042TVRoQ2JDVXlRa3hRUTFSdkpUSkdORVZZTUdWTFlsZHRlVlZ0UkVwMFRFMDFWQ1V5Um1FeVExRjVRMk16WlhVelJqRnVWbFpSSlRKQ2VXRWxNa0prVFRBMk9ITk5XSGR6T1RORlltaHFSVXBPWTB3eGJGQjVXRWwwTmtSaVRuZExXR0ZuZFZwQldYaE1KVEpHYWxWRFZFZEZRelZ3VHpsMVVreENUakJ6UkhoT2JsWTBSU1prYjNkdWJHOWhaRUZ6UFZvdFdtbHdVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdaRFJ5YW1vMmNHWXdZMkZxZHk1amJHOTFaR1p5YjI1MExtNWxkQ1V5UmxvdFdtbHdVMlYwZFhBdVpYaGw=

http://www.headbundlesfarm.com/WVl6OTRQVlpVZDFReGQwcGhVVWRuYWt0bU5EaEhURlpMUm10SlQyeG9Wa2RtVVRZbE1rWjRkV1l6ZDI5dFpHeGpUU1V6UkNaalBXOVNXR3BCZUhwQmJYRjJiVkJaVUdWNVdUZDBhRzk2ZEZGb1VrY2xNa0pwTUZaUlMwRTBNa0ZuWlhwSFRWSkNkV2RYWjBsSVQwaFdkWEpOZGxaaFdFVjNkRE5TWWs4Mk5WaG1PSFJzYVd0MVZqSmxabGx4YVVoNVZ6RllUbTVFVUV0eGFFMDBiRWxRY1VSNmVtWkZXalJMTTNkVGQzRkJha0poWW5CeVYwRTBNMU1tWkc5M2JteHZZV1JCY3oxYUxWcHBjRk5sZEhWd0xtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbVEwY21wcU5uQm1NR05oYW5jdVkyeHZkV1JtY205dWRDNXVaWFFsTWtaYUxWcHBjRk5sZEhWd0xtVjRaUT09

http://www.headbundlesfarm.com/WVl6OTRQV2R3TmxwMk5HOWlaMkpaYkRsRVMzZERVRFowTlRBNU5HUjZhVWhRVW5BeGFFMWFja1UxU2tsWGFVa2xNMFFtWXoxeWFFRnNjSEpPYmtReGIybDJPVk5SU1Rsa1ZHaGxabEpzY2xkaWF6Wk1SbmhqSlRKR05YbDFZVFJHZWs0bE1rSXpkVmREUlhCcmNEQjZXVGxpYjBkUFZGVTRVREJTV2tSa05XdGpKVEpHVFRkUFpYVkhZbTVGZDBJekpUSkdjMDFRZENVeVFpVXlSbTQ0YUU5T2MzTnBWRFJuVmtGcFVGSjBRME5oZDNnbE1rWk9PSEZGVTBaV05ua2xNa0pMWTFJbVpHOTNibXh2WVdSQmN6MWFMVnBwY0ZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1RMGNtcHFObkJtTUdOaGFuY3VZMnh2ZFdSbWNtOXVkQzV1WlhRbE1rWmFMVnBwY0ZObGRIVndMbVY0WlE9PQ==

http://www.headbundlesfarm.com/WVl6OTRQV3h4Vm1kSVoyUlBOVEJKY1RCTk1UaFhhMDQxY21FbE1rSnRURWc0YzFFNU5HTlBaWFZZVW1WbmExaFBheVV6UkNaalBVUXhlbmh1UTJoalIwZEZWa05QV1hac1IxWTBSMUJwVlhkS1kyZFNPVXhoUTFFMVJVa3dUa1pGT1hGWWFFZGFRU1V5UW05VlpGWlhjMnA1TTNGNVVtczVlRlJrZEdGc2JYQkpKVEpHVFV4SmVHbHRWRWhsTUVkR1dWTkRjMHQ2VjJKWWRFRTRUemxKVEVOc1dYSnhja3h5VkdkWWFYVWxNa0pHU1ZONU5GRjROME54TmtRd0ptUnZkMjVzYjJGa1FYTTlXaTFhYVhCVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaa05ISnFhalp3WmpCallXcDNMbU5zYjNWa1puSnZiblF1Ym1WMEpUSkdXaTFhYVhCVFpYUjFjQzVsZUdVPQ==

Latest 30 of 143 download URLs

Remove z-zipsetup.exe - Powered by Reason Core Security