hss-5.4.3-install-plain-773-plain.exe

Hotspot Shield

The application hss-5.4.3-install-plain-773-plain.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from biblprog.com.
Product:
Hotspot Shield

Version:
5.4.3.9703

MD5:
3ccb746f53981e86eca413856c075972

SHA-1:
c1a4707a07c9214633189612dd000a0a5cf912be

SHA-256:
a48028c2f8408e626b72d6f88338a1d4ddcfe6fbb6d1137daeb76708e119d7e2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 9:28:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.HotspotShield.Installer.Meta (L)
16.7.14.0

File size:
11.7 MB (12,291,392 bytes)

Product version:
5.4.3.9703

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\hss-5.4.3-install-plain-773-plain.exe

File PE Metadata
Compilation timestamp:
12/27/2015 9:55:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:JBzWDrlluS33ccXyysPDpLEMCSgdzQA/WySPHnlN0QvxS/j6fx8SDo3RsNC4u5+R:bzArRnLob61SgRQRySHnlGQory3o3RwR

Entry address:
0x327D

Entry point:
BF, 66, 36, C2, 67, 8D, 05, EB, A5, 3F, 1D, 34, B1, 74, 04, 8B, DF, 24, D7, 0F, B6, CA, F3, 84, E4, 85, EF, 52, 68, F1, 94, 83, 00, 21, D5, E8, 00, 00, 00, 00, 58, 89, C1, 86, D1, 80, C2, 85, 50, 68, 4A, 65, 63, 00, 69, EA, 0E, E7, C7, A5, C6, C3, 51, 69, ED, 1A, 1A, 73, 33, 0F, B7, F8, FF, CF, 01, D5, 42, 69, D6, C8, BF, 87, 9A, FE, CA, 8B, E9, 50, 0F, AF, D0, 0F, AF, EB, 85, C6, 5B, FE, CA, 42, 13, EB, 53, BE, 67, 9D, 28, 65, 5F, EB, 08, F7, C6, C1, 08, DB, CB, 33, D7, EB, 02, 87, F3, 33, CF, FE, C3, 4E...
 
[+]

Entropy:
7.9956  (probably packed)

Code size:
24.5 KB (25,088 bytes)

The file hss-5.4.3-install-plain-773-plain.exe has been seen being distributed by the following URL.

Remove hss-5.4.3-install-plain-773-plain.exe - Powered by Reason Core Security