etypesetup_v1.0.1.6443.exe

DSNR Media Group

The application etypesetup_v1.0.1.6443.exe by DSNR Media Group has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from landing.etype.com.
Publisher:
DSNR Media Group  (signed and verified)

MD5:
7b311baf2d1d03a2a74ff812dd84dde6

SHA-1:
b7c2afb722674b0832718e731d1817059448b09f

SHA-256:
e24e836f218516629eeddbc5309c0b639182dd79e13ce7fd60ad99b5a39f457a

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 4:48:10 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
8.0.319.0

F-Prot
W32/InstallCore.S.gen
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.2886.0

Reason Heuristics
PUP.DSNR.DSNRMedi.Installer (M)
16.7.3.11

File size:
1.1 MB (1,193,800 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\etypesetup_v1.0.1.6443.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/4/2013 12:00:00 AM

Valid to:
2/4/2014 11:59:59 PM

Subject:
CN=DSNR Media Group, OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=DSNR Media Group, L=Raanana, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
728AB12B430CC198ECD6CC4C4790F216

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:kTDL7vaRF9NpvNXU0x0K31gWGWFSGrGGJ:ivrtf0WQSwG

Entry address:
0xDA070

Entry point:
55, 8B, EC, 83, C4, F0, B8, F0, 6E, 41, 00, E8, EE, FA, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
885 KB (906,240 bytes)

The file etypesetup_v1.0.1.6443.exe has been seen being distributed by the following URL.

Remove etypesetup_v1.0.1.6443.exe - Powered by Reason Core Security