z-zipsetup.exe

Lenasepuc

Colifile SLU

The application z-zipsetup.exe, “Lenasepuc Setup ” by Colifile SLU has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.headbundlesfarm.com and multiple other hosts.
Publisher:
Kecu   (signed by Colifile SLU)

Product:
Lenasepuc

Description:
Lenasepuc Setup

Version:
1.6.2.0

MD5:
b102aa8d263927c81b2ef96a8e652edb

SHA-1:
7945251583433228be9b3b3e8d071cf0a3a43de7

SHA-256:
08d6d75c104e2c571ff3ec52be2200d89fa2f89e8c87df33097a30f17669fec6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 10:45:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.Colifile.Installer (M)
16.4.22.17

File size:
940 KB (962,520 bytes)

Product version:
5.2

Copyright:
File

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\z-zipsetup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
11/18/2015 4:00:00 PM

Valid to:
11/18/2016 3:59:59 PM

Subject:
CN=Colifile SLU, O=Colifile SLU, L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1D8228BD3D6A0EADA24B1453F4593406

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:+QPvETEbn364mHWrF0FEc75lD0Gl2poCC3w:+oPnq4mHWZc1lD0GjCCg

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9380

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file z-zipsetup.exe has been seen being distributed by the following 50 URLs.

http://www.headbundlesfarm.com/WVl6OTRQVWt3Ymt0V1pHTnBlRTBsTWtJM2JFa3paM2RPVjJkcVUwNVJZa1J1ZDB0d1VHVnpjbWxSUkV4UVVrSlljeVV6UkNaalBWWlBVV3gwU0ZOUmEyMUNjVm95UlNVeVFteDJNVnA2SlRKR1JtZDNabmNsTWtKdWJHOXNhbWtsTWtaSk9FZHNlVFl3UkhsTllra2xNa1pGVm1jNFVuYzFNaVV5UWt4cU1saDNkRlpJUWxaU1FrcENjalZZV0U1cGEzQkZkemxpZDFZME1scE5VVGhQV1RaVVQwOGxNa1pvYTFSeWIwaGFaV2xpVjBaU2RYZGFPSEkzZGxoaVMwcHZWRFJ6TUhFbVpHOTNibXh2WVdSQmN6MWFMVnBwY0ZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5OMFlYUnBZM0p5TG5vdGVtbHdMbTVsZENVeVJuTmtZaVV5UmpNMkpUSkdXaTFhYVhCVFpYUjFjQzVsZUdVPQ==

http://www.headbundlesfarm.com/WVl6OTRQWEZJYTNONGJXVXhOR1IzT1hNMVFtaFplbE55WVVKTkpUSkdaRFUyYjBSdU5GbFJVV1Z3VGxoUVNWaE5VU1V6UkNaalBUTklUSElsTWtaQ2NrcHBlbWRwYkRCWlRHTkxjazhsTWtKbWMzSlRaVFJZUkRkd1dUaExTMnR0V1RsRFdDVXlSbmhvVDBWblIzTlFhbUkzWmt0a1FVa3lPVk4wZFZreVFVY2xNa1pzUTBORVRVeHFaMEZGYUhKeFJHbDFkVk1sTWtaQ1prNWpUVkZ4WmtKMlpFYzRUa1kyWmtOVVJWVk1ObU5vTTA5dlQzVnZjRGRSU0ZwblJYUlVNQ1prYjNkdWJHOWhaRUZ6UFZvdFdtbHdVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdjM1JoZEdsamNuSXVlaTE2YVhBdWJtVjBKVEpHYzJSaUpUSkdNellsTWtaYUxWcHBjRk5sZEhWd0xtVjRaUT09

http://www.headbundlesfarm.com/WVl6OTRQVFpEVlc5c1JXMVNjM3B1TkdkUlVsWkxWa295U2pRNGFGYzJXWFJDY2xaNE1tODVVMm96VlhSSGQzY2xNMFFtWXoxVE4yc2xNa0kzY0RoSU1HaENiVTlITTJkRVExcDRiVTVZTTNSME1DVXlRaVV5Umtac2VXMVVWREZ4ZEZKQ1UzTTFhVVZ0VUdoa1NFZHJKVEpHVFdSRVpXdE9XR3BNVUNVeVJsTkpiREZrSlRKR1FYaE1VbXBzU0VKVVEzTk5RalZZTURsek9WUjBkM0pzYTFvM1NIWjJOVkFsTWtKYVFrSlFiMGRNVjBWaU4wdFBla05vZWxSU1ZVaDBia0pHSm1SdmQyNXNiMkZrUVhNOVdpMWFhWEJUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p6ZEdGMGFXTnljaTU2TFhwcGNDNXVaWFFsTWtaelpHSWxNa1l6TmlVeVJsb3RXbWx3VTJWMGRYQXVaWGhs

http://www.buildworldfiles.com/WVl6OTRQVkY1YWpGelRqbERWa1JhZEU1UVZuWXhiemRyVUZONlYyRktVRlZyUzBoRlEwbHNRMnR5VVhKclVra2xNMFFtWXoxUldVNUhZMVYwT0ZKUGVrUnVXa3BYTTBreVJrVmtXRmRTUkdkck5UTnlURzVVVURBME4yUWxNa0p3Y1doTWNETnBaelpPZEZCUlQxTnJkems1TjBwcmVsQTJaM2tsTWtaUE1IYzFOVXRYVEZWS04yUnBhbHBDVWtSemVuVkhZMUowWnpZM1RIbDFhamRNY1c1dlluTkNhVEJDYm1VemRHVjNkV3g1T1RKVU56SXphbmdtWkc5M2JteHZZV1JCY3oxYUxWcHBjRk5sZEhWd0xtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbk4wWVhScFkzSnlMbm90ZW1sd0xtNWxkQ1V5Um5Oa1lpVXlSak0ySlRKR1dpMWFhWEJUWlhSMWNDNWxlR1U9

http://www.buildworldfiles.com/WVl6OTRQVmxVT0VSS1JFOURPU1V5UWpacVNVZHdaVUpLT1V0c2RUVnJSR013Ymt4QlZEbFdka0kxSlRKR1VYSjZKVEpHSlRKR1p5VXpSQ1pqUFVGdVMzWm1Ta2N5TTBRM1pWUnJPVTFMYjBWaGNVMUpjbUZwT0d0dmRqRnFkRVpSYTBsQ1ozTkhXVE5UVkVkT2NIcDBXR0ZxWTFWcGVWcEhhbEkyUjBSbmRFWlhPV1F6VEVSV2REYzJPSGQyZVhaU05GZ2xNa1lsTWtKVWRrcENla2xsT0hGSk5YRk9ORkZKTmpodGJrcEdUVTF0VGpoTVdHZFhRMWhzYXpjbE1rSnJWamxWSm1SdmQyNXNiMkZrUVhNOVdpMWFhWEJUWlhSMWNDNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p6ZEdGMGFXTnljaTU2TFhwcGNDNXVaWFFsTWtaelpHSWxNa1l6TmlVeVJsb3RXbWx3VTJWMGRYQXVaWGhs

http://www.headbundlesfarm.com/WVl6OTRQVzloVDJaelZFTmlRMFp3VVVoMGFXSllVRzV3WmpGblRHWTRXVXhSZDBkSE5WZE5jV2N4VmpaTVZsRWxNMFFtWXoxSWRHdGtVR2xaYjNBbE1rSm1iekZwWlZremIyOUZhbmxUTVdSbVN6SnlVaVV5UmtNME9YaFhWM1p3ZFc5bmRGTmphbXN6YUZsNlV6RnBTbEpOUjNnbE1rSktlSGx0ZG13M1FUZHJiRFJtYmxsbGJWbGxkRGxIVm5SWE9VSkpNMmxZWldkQ2VYVnlPRTFvY2tsbFJFOUlPU1V5UWxwQ2RtWTJTalJ6Wld0TUpUSkNWRGRuZFZjMlIxQW1aRzkzYm14dllXUkJjejFhTFZwcGNGTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuTjBZWFJwWTNKeUxub3RlbWx3TG01bGRDVXlSbk5rWWlVeVJqTTJKVEpHV2kxYWFYQlRaWFIxY0M1bGVHVT0=

Latest 30 of 152 download URLs

Remove z-zipsetup.exe - Powered by Reason Core Security