3dem_setup.exe

InstallShield

Visualization Software LLC

The program is a setup application that uses the InstallShield Setup installer. The file has been seen being downloaded from semhur.free.fr and multiple other hosts.
Publisher:
Macrovision Corporation  (signed by Visualization Software LLC)

Product:
InstallShield

Description:
InstallShield (R) Compact Installation Engine

Version:
14.0.0.223

MD5:
46928665acf9bfe68273a159f8c24d4e

SHA-1:
a71f17219d26905870f94cb1fe4be26d183dc99f

SHA-256:
4105a446774be6f33ad11e7df3ab24b902708250c6e78d8067d6a84ba46f7ea0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/7/2024 8:22:51 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

File size:
4.1 MB (4,334,128 bytes)

Product version:
14.0

Copyright:
Copyright (C) 2007 Macrovision Corporation

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\3dem_setup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/22/2007 2:00:00 AM

Valid to:
10/22/2010 1:59:59 AM

Subject:
CN=Visualization Software LLC, O=Visualization Software LLC, STREET=76 Mourning Dove Drive, L=Stafford, S=VA, PostalCode=22554, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00E3EF445530FA08E00C5DC7D22B2CDE38

File PE Metadata
Compilation timestamp:
7/17/2007 5:02:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
98304:5EurNrK5gJAGecEwPd/RTJGMC8UBB+TXG0G3g20IC6yc8LoIG6:ysrK5gJPOwPBBwMC8ICHGwpN/oI

Entry address:
0x1000

Entry point:
B8, B8, 78, 42, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 23, 41, A7, F7, 7F, 41, B5, 8B, 26, 46, 58, 99, D6, 2F, FC, E1, F1, 9D, 94, 48, 00, 4A, F8, 00, F5, EA, D4, C1, 0F, 05, 3C, 23, 70, AE, 68, 86, 88, 3E, 78, E8, 80, 09, 36, 8C, 50, 2D, F8, F9, EF, 67, CD, 18, 7F, DF, 9C, 17, 80, EE, B8, 17, E8, 03, 42, 5A, 28, C2, 1F, 8D, 9B, 81, 20, DF, 3F, F6, C2, 75, B9, 41, F2, 56, 22, 5D, 0D, B3, 50, 87, 88, 41, 57, B4, 0A, BC, 43...
 
[+]

Packer / compiler:
PECompact v2

Code size:
110.5 KB (113,152 bytes)

The file 3dem_setup.exe has been seen being distributed by the following 2 URLs.

Scan 3dem_setup.exe - Powered by Reason Core Security