isafe_setup.exe

The application isafe_setup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.po114.org.
MD5:
5b8d8fd128bf187bda0487d000979092

SHA-1:
ebdacd3274daae10eb6201c14acc6b28130cc883

SHA-256:
86fccb47b348704f5fac0ed54434c5d27eb817b4bcfd9f8670aa215dade8fe01

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2024 5:52:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.iSafe (M)
16.7.8.9

File size:
6.1 MB (6,420,608 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\isafe_setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
98304:eGL/MpaCmNAIXSAlsFNA7XjYTZNX4kwW8IWTGibqBnjKfanTEbRRfIGB+boaZ/fa:OUNlXxyssPX4kb8Iubwj2FNBVaI

The file isafe_setup.exe has been seen being distributed by the following URL.

Remove isafe_setup.exe - Powered by Reason Core Security