isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.po114.org.
MD5:
718c5dfca9d8b073e56342e58b9987e2

SHA-1:
e0c4562807ee37a2161e847546f1e175d9047524

SHA-256:
465ecfc182dce790d29d0c76b6d037a4db9db47eb836ff102f17beaaefb53552

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 2:50:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.iSafe (M)
16.7.8.9

File size:
8.7 MB (9,143,840 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
196608:tUIGCtOznhirXCbW/Wu0ljaSfdVWxFPLXacsDMZnyI6FeEHxhAe:qIGuUnKXCoW35WxFPLruI0rH3B

Entry point:
F5, 83, D4, 9A, F3, 70, F2, F6, AB, 2D, 0A, 00, 4F, B4, E7, 17, 1B, C2, C1, 8C, C8, F7, BA, 62, FB, 11, 33, 06, 10, E5, BD, 91, 43, 1A, E0, A3, D3, 97, 84, E3, E2, 50, DC, B6, BA, E3, F8, 3E, BD, 62, 6B, 16, 74, 87, 65, 1E, 1A, 7E, 17, 67, 59, E8, D2, F0, 7E, BF, CC, 76, BA, B7, 18, 91, CE, E5, 9B, C9, 2E, 43, 34, 06, 4E, 4D, 65, 89, 5B, 01, EF, 88, 13, F0, 98, BB, 70, 1C, 93, 47, F3, 21, E0, D1, 56, 2A, 10, 23, C2, 8B, 93, 84, 60, 85, 11, 2A, 97, CF, C5, 34, 34, 91, 0F, 3F, 38, C9, C8, CA, F7, 38, D4, 3F...
 
[+]

The file isafe_setup.exe has been seen being distributed by the following URL.

Remove isafe_setup.exe - Powered by Reason Core Security