cloud_backup_setup.exe

The application cloud_backup_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from aff-software.s3-website-us-east-1.amazonaws.com.
MD5:
9b94c742843cad11ffda99e4e3be45b4

SHA-1:
8d9e780c880c265d6baa6ae961a16ed6be63ef7c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 4:52:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.JDIBackup.Optional.Installer.Meta (L)
16.1.14.11

File size:
297.2 KB (304,376 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\cloud_backup_setup.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:6er4OUaD6ryWrj+C73LDAvaz2IeUlxoWXmTfH9Ujq:pUaD6rymLd/hWW2H3

Entry address:
0x30FA

Entry point:
85, E9, 53, 57, 3B, CF, 73, 0A, 84, E7, B5, 4D, 81, D2, 63, 68, AE, 5E, C6, C7, 53, 1C, 49, 8D, 05, 77, 63, DE, E4, B7, C1, 88, D5, 84, D8, 32, D8, 81, EA, 9A, 0F, 00, 00, 0F, BE, C6, 89, CB, 81, EA, C9, E1, 00, 00, 81, DF, 63, 1A, 45, AC, 14, E1, 8D, 35, 66, 0A, 7A, 3A, 69, C2, 2D, EF, 74, 37, 77, 05, 22, F0, 0F, B7, E9, F6, C7, 23, C7, C0, BE, E3, 0D, 82, 14, 10, E8, 00, 00, 00, 00, 5B, 8D, 2D, 29, 9D, DC, 09, 88, D1, 8D, 0D, D5, AC, 6E, FC, 03, F1, 81, F6, 62, 99, D1, A0, 76, 02, F3, F3, 69, C5, 8B, 78...
 
[+]

Code size:
23.5 KB (24,064 bytes)

The file cloud_backup_setup.exe has been seen being distributed by the following URL.

Remove cloud_backup_setup.exe - Powered by Reason Core Security