isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.po114.org.
MD5:
ac5a2f3b1781c8e9254c52fff88c86ec

SHA-1:
359bf8bd88f0eb0b2f5ea13a27d7fb350315ea5a

SHA-256:
7772cde7dddf6e35a4e8fcccd30700f43c8890ef1c361ac291d37a330757c5e3

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 2:57:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.iSafe (M)
16.7.8.9

File size:
6 MB (6,274,000 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
98304:5KncxTqY2TIr9jnmDsAVBy8ztJmsSG8kyhZDA7hjOy7w2wYf4s72M:5+ITq3cYsqy8z3Wt6SvObSM

Entry point:
EE, AC, CE, CF, 2F, 7D, AD, 8C, EC, 24, 55, 42, B1, CB, 97, 88, 2C, A9, F9, 0A, 7B, C5, D2, 90, 1B, 0E, 35, BE, 26, CD, A7, 69, 43, 1A, E0, A3, D3, 97, 84, E3, E2, 50, DC, B6, BA, E3, F8, 3E, 50, 5A, 7C, DA, AA, DB, D2, 8D, 08, 4A, 40, C1, F3, A7, 63, 40, 02, 34, C1, 16, F5, 83, E0, 3B, F9, 34, 92, 12, F7, 82, A3, 5D, 26, 9F, 5A, 1B, 26, 64, 15, 5A, 0E, A2, AF, A3, 30, 1B, 19, 9F, E5, 9E, 1D, 3A, 0E, 1F, 3F, 72, 0D, 01, A7, 1D, AE, FE, 20, DD, BC, 0A, 91, 83, ED, 2B, D0, 9D, A1, 68, C9, 21, 6F, 26, 2B, 6B...
 
[+]

The file isafe_setup.exe has been seen being distributed by the following URL.

Remove isafe_setup.exe - Powered by Reason Core Security