codecperformersetup.exe

The application codecperformersetup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.appoder.com a known adware distribution point operated by Softango Technology LLC.
MD5:
1cf8de69d5288e18844b48e02187f918

SHA-1:
e1e0decce985af7518579da0f86b76810ccdc918

SHA-256:
ef7002424e452a794ce8b154f82edd75aff451a9e98059fda2d3bfa73dda9741

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 8:25:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Win.Reputation
15.12.12.11

File size:
1.1 MB (1,154,949 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\codecperformersetup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:1wgFgx6/ZmSyl7V2LOx5CCIcIEOZ7ma9MI90OAG6Rd39J:SUgxOmSCacCCIcE1ihOAzL3n

Entry point:
50, F7, CC, 44, 3E, E7, 20, D8, 24, A1, D1, AD, EA, 51, 7A, 6B, 5E, A3, 37, 19, E8, 0C, 6E, 61, 72, F1, 08, DE, 11, C1, 84, CA, F9, 4C, 25, AB, 52, EC, 28, 27, B9, 11, 86, 7F, D3, 37, D1, 20, 2B, 69, B6, B0, 82, E4, B8, 9E, 62, 81, 1E, BE, C8, D0, D3, 86, D7, EB, 96, D7, AC, 88, D6, C9, 31, 2B, CE, EB, 83, E9, 6E, 03, 09, F7, 50, 7F, 41, 52, 4A, A8, C1, 5F, 9B, A8, 7E, 3C, 21, 28, B5, AF, 59, 3D, CC, E9, 81, 74, B5, 82, 12, A3, 10, 86, CC, 03, 01, 33, EE, D7, E3, 52, 20, 91, A4, 86, 08, 9A, FD, 9E, 5A, DC...
 
[+]

Entropy:
7.8895  (probably packed)

The file codecperformersetup.exe has been seen being distributed by the following URL.

Remove codecperformersetup.exe - Powered by Reason Core Security