isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.po114.org.
MD5:
205db9df3a1c01ed517251c65dfe9060

SHA-1:
738ac4e26d3b44ec7cd885a57dfa893772b88428

SHA-256:
2ee708ea51ccab2e942455673fe585af1a9288d0a5fdd7b3dab6d7d79df40714

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 1:29:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.iSafe (M)
16.7.8.9

File size:
5.4 MB (5,665,760 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
98304:vL8Y1qIfYT12jd6JJ5zw/W50nGU2sISa2tmhn1kqkXF8M2ATZB93lgN0lP/3u:vL8Y1TAT128P5zF6GQID2tmh1krXF/Zi

Entry point:
BF, 3E, 10, 11, 76, F6, 2C, D6, 75, CC, D2, 66, B3, 99, A0, 16, 3C, CF, 88, A3, 71, 9C, 45, 78, E4, 8B, 8B, C9, B8, 4F, 30, 94, 43, 1A, E0, A3, D3, 97, 84, E3, E2, 50, DC, B6, BA, E3, F8, 3E, 02, E2, CF, 67, 06, A1, 95, 64, EC, 90, 87, 37, 6B, E8, B9, EB, F3, 8B, B5, 0E, FB, B2, D9, 6C, 64, A4, 69, 7D, 34, D7, E2, CA, 8C, E5, 4D, 6E, D0, AF, CA, FE, 16, 9E, 51, DD, 15, 08, 9F, 70, 34, 81, B3, D9, F8, F0, 62, EE, 70, 1D, 2B, 50, C1, 14, 55, 55, BC, 0A, 91, 83, ED, 2B, D0, 9D, A1, 68, C9, 21, 6F, 26, 2B, 6B...
 
[+]

The file isafe_setup.exe has been seen being distributed by the following URL.

Remove isafe_setup.exe - Powered by Reason Core Security