anti-malware-setup.exe

SafeBytes Anti-Malware

SafeBytes Software Inc.

The application anti-malware-setup.exe by SafeBytes Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from safebytes.cdnsecured.com.
Publisher:
SafeBytes Software  (signed by SafeBytes Software Inc.)

Product:
SafeBytes Anti-Malware

Version:
1.0.2.0

MD5:
17328fb6ad1205d2a47752f9b80afec8

SHA-1:
1fdd78de73bb35b1cf03afc2c229aeb3d2ca4f14

SHA-256:
8961a6826ffdb9180842b5de59d1235e549136bcc84f262a783632a8d52645ff

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 7:26:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
17.2.28.1

File size:
962.5 KB (985,648 bytes)

Product version:
1.0.2.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\anti-malware-setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/4/2017 6:00:00 PM

Valid to:
1/8/2019 6:00:00 AM

Subject:
CN=SafeBytes Software Inc., O=SafeBytes Software Inc., L=Montreal, S=Quebec, C=CA, PostalCode=H3A 2A6, STREET="2001 Boulevard Robert-Bourassa #1700", SERIALNUMBER=867835-9, OID.1.3.6.1.4.1.311.60.2.1.3=CA, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
03BD7F98F3A73E270141C5CE0A780A6B

File PE Metadata
Compilation timestamp:
1/2/2017 9:26:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x308700

Entry point:
60, BE, 00, 10, 64, 00, 8D, BE, 00, 00, DC, FF, C7, 87, 10, 4C, 27, 00, 15, 87, 77, 6F, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.5930

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
800 KB (819,200 bytes)

The file anti-malware-setup.exe has been seen being distributed by the following URL.

http://safebytes.cdnsecured.com/download/.../?tid=affiliatewire_pennysoft-asubid_58-KPTU

Remove anti-malware-setup.exe - Powered by Reason Core Security