pivot_setup_ic2.exe

The application pivot_setup_ic2.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dl.xetapp.com and multiple other hosts.
MD5:
96546e1f5ca397fba78924923528e0e9

SHA-1:
38966d1e7521c5cf598b446690dec3d970d1759b

SHA-256:
03bb7934ede8f994dcca774e2009b142c1127e0c420447c52fc3568aeadcf9e1

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/23/2024 5:57:03 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
14.03.25

Avira AntiVirus
7.11.138.84

Bkav FE
W32.Clod6c2.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt
17970

Dr.Web
Adware.InstallCore.80
9.0.1.084

ESET NOD32
Win32/InstallCore.AZ (variant)
8.9574

Fortinet FortiGate
Riskware/InstallCore
3/25/2014

F-Prot
W32/InstallCore.W.gen
v6.4.7.1.166

K7 AntiVirus
Riskware
13.176.11524

Rising Antivirus
PE:Trojan.Win32.Generic.14074943!336021827
23.00.65.14323

Sophos
Install Core
4.98

VIPRE Antivirus
Trojan.Win32.Generic
27620

File size:
1.1 MB (1,170,944 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:0VpIGWeOwTLpIykB0tkK9gGyXVYMbLXUrdcszFZx8iNbYM5kY:0VpwELpu0t5/yXVbg+4zWsbt5

Entry address:
0xD5850

Entry point:
55, 8B, EC, 83, C4, F0, B8, 9C, 5D, 41, 00, E8, 82, D4, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7081

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)

The file pivot_setup_ic2.exe has been seen being distributed by the following 2 URLs.

http://dl.xetapp.com/downloads/software/graphics/.../pivot.setup.exe

Remove pivot_setup_ic2.exe - Powered by Reason Core Security