horizon-setup.exe

SAFE INSTALL SOFTWARE

The application horizon-setup.exe by SAFE INSTALL SOFTWARE has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from files4.downloadtrunk111.com.
Publisher:
SAFE INSTALL SOFTWARE  (signed and verified)

MD5:
ed3112c135f2350ae428ec8870ee8803

SHA-1:
13adfa740ce2b391d4156f54e0125bdbee95f06b

SHA-256:
7f75e305d8105da6f2ef440a4225321aa5f0de292823231f3a611abb44a69e2b

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
5/4/2024 12:20:50 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.DownloadAdmin
2015.06.12

Avira AntiVirus
TR/Agent.669160
8.3.1.6

AVG
Generic
2016.0.3081

Dr.Web
Trojan.SkypeSpam.5910
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.L potentially unwanted application
7.0.302.0

F-Secure
Win32.Sality.3
5.14.151

IKARUS anti.virus
Trojan.Graftor
t3scan.1.9.5.0

Reason Heuristics
Threat.Win.Reputation.IMP
15.6.11.13

VIPRE Antivirus
Threat.4150696
40830

File size:
653.5 KB (669,160 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\horizon-setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/18/2015 8:00:00 PM

Valid to:
5/18/2016 7:59:59 PM

Subject:
CN=SAFE INSTALL SOFTWARE, O=SAFE INSTALL SOFTWARE, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5591FE91109E0E8E18F34E77C30B1AB9

File PE Metadata
Compilation timestamp:
5/11/2015 2:14:16 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:E9cazLCHa4Aq9C5pdDHG850PBkHh6wrZkbY9380QpkY6sj8eCaRV4gSQTOBT:4caz+Hafq9CFDH3OmB6QZkM3cCS8KinT

Entry address:
0x1BB4

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, E0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, E8, DC, 51, 00, 00, 53, E8, 50, FD, FF, FF, 59, FF, 15, 50, 77, 40, 00, 68, 01, 80, 00, 00, FF, 15, 70, 70, 40, 00, 53, FF, 15, 4C, 77, 40, 00, 6A, 08, A3, 98, 2C, 42, 00, E8, B9, 09, 00, 00, 53, 68, 60, 01, 00, 00, A3, 00, 3D, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 73, 74, 40, 00, FF, 15, 9C, 71, 40, 00, 68, 68, 74, 40, 00, 68, 00, 35, 42, 00, E8, AB, 08, 00, 00, FF, 15, 6C, 70, 40, 00...
 
[+]

Entropy:
7.9744

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file horizon-setup.exe has been seen being distributed by the following URL.

Remove horizon-setup.exe - Powered by Reason Core Security