focusrite control-2.1.6.exe

Focusrite Control

Focusrite Audio Engineering Ltd.

The application focusrite control-2.1.6.exe, “Focusrite Control Setup ” by Focusrite Audio Engineering has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from sync.focusrite.com.
Publisher:
Focusrite Audio Engineering Ltd.   (signed by Focusrite Audio Engineering Ltd.)

Product:
Focusrite Control

Description:
Focusrite Control Setup

Version:
2.1.6.1344

MD5:
b4f6ccfd8a26faaf79233ae79f1bee05

SHA-1:
46db30a37e4583844f3f328d06508134fc8c8780

SHA-256:
52ba23c2261f06d3c1ab0baa41d2a01e64f9ac0d845fd003ae1ec2f3661f0cf3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/11/2024 8:28:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.1.23.4

File size:
12.3 MB (12,913,032 bytes)

Product version:
2.1.6

Copyright:
Copyright(c) 2014-2016 Focusrite Audio Engineering Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/2/2015 1:00:00 AM

Valid to:
10/10/2018 1:00:00 PM

Subject:
CN=Focusrite Audio Engineering Ltd., O=Focusrite Audio Engineering Ltd., L=High Wycombe, S=Buckinghamshire, C=GB, PostalCode=HP123FX, STREET="Windsor House, Turnpike Road", STREET=Cressex Business Park, SERIALNUMBER=02357989, OID.1.3.6.1.4.1.311.60.2.1.3=GB, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0D0088899A33CB95C8EC02DFDB89926A

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file focusrite control-2.1.6.exe has been seen being distributed by the following URL.

https://sync.focusrite.com/s/.../download

Remove focusrite control-2.1.6.exe - Powered by Reason Core Security