computerupdatersetup_cb_installer.exe

Computer Updater

SafeApp Software, LLC

The application computerupdatersetup_cb_installer.exe by SafeApp Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.safeappsoftware.com.
Publisher:
SafeApp Software, LLC  (signed and verified)

Product:
Computer Updater

Version:
3.0.70

MD5:
303f8e5800b82e4b9eec154fa7584b49

SHA-1:
3a102abc8a061aac8fbe56cf6b32b7474b3d4f48

SHA-256:
71c3d2fe0568e1d72524429b218e85df8af66ed778276e571f93279b1cb72145

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/2/2024 6:59:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SafeAppSoftware.Installer (M)
16.1.21.7

File size:
7.4 MB (7,727,376 bytes)

Product version:
3.0.70

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\computerupdatersetup_cb_installer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/6/2015 7:00:00 PM

Valid to:
1/7/2016 6:59:59 PM

Subject:
CN="SafeApp Software, LLC", O="SafeApp Software, LLC", L=Harrison, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
057EF95AEE96D23091760F07BE8E21F1

File PE Metadata
Compilation timestamp:
10/7/2014 12:40:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:NmfgkMhAQ8a7WhRK6uOdfUDmD2cqf1RTdND:NmfgZr8BqUl6c0vn

Entry address:
0x335A

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, B8, 92, 42, 00, E8, 15, 2F, 00, 00, A3, 04, 92, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, A8, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, 00, 82, 42, 00, E8, 80, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 6E, 2B, 00, 00...
 
[+]

Entropy:
7.9996

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file computerupdatersetup_cb_installer.exe has been seen being distributed by the following URL.

Remove computerupdatersetup_cb_installer.exe - Powered by Reason Core Security