isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.goplayer.cc and multiple other hosts.
MD5:
804404ff61bb3b15b371922f2a405cf0

SHA-1:
cb268d24eb37ce7f83644ca68931f466a721ba1e

SHA-256:
62f88824f601476e210b7c8bc2e68f4a4ee1bf6e3a500415d614ff1b9a6c07c0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 6:53:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.iSafe (M)
16.7.8.9

File size:
8.7 MB (9,078,416 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
196608:zWxWYY2Cwa6Kyq5JuIP6zRX6fqm+M4SdbdvuvzB7wNW2oLIBF:zJ2Va6KHH9kRXiq3n6uvGToLIBF

Entry point:
15, 0F, 72, 19, 1D, E7, 5A, 6B, 85, 16, 5F, F4, 17, E1, 18, E1, 1C, AF, FF, 93, 56, 44, E6, C1, 4D, D7, 60, 1D, CA, 3A, FB, 34, 43, 1A, E0, A3, D3, 97, 84, E3, E2, 50, DC, B6, BA, E3, F8, 3E, 17, 7D, F1, 41, E3, A1, B7, 9E, 89, 49, D2, BD, DE, 37, 23, 61, 37, 6E, A2, E4, 24, 39, C8, FF, 4E, A2, F3, 99, 93, 07, ED, 9C, 5B, 34, E5, BC, 42, 56, 41, AB, 62, 52, A0, 84, DC, 1A, B8, F6, D6, 39, FD, 57, 64, 12, 5F, 3D, B8, 1D, 48, B6, 2B, EA, 56, 6E, BC, 0A, 91, 83, ED, 2B, D0, 9D, A1, 68, C9, 21, 6F, 26, 2B, 6B...
 
[+]

The file isafe_setup.exe has been seen being distributed by the following 2 URLs.

Remove isafe_setup.exe - Powered by Reason Core Security