safe_v1_setup.exe

The executable safe_v1_setup.exe has been detected as malware by 12 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from download2158.mediafire.com.
MD5:
ce90408f5c9872d9f4d72f2e0a67e9fa

SHA-1:
f9b6b052684d258f090a1b02314b9a88a660dc01

SHA-256:
45c73e91605e2f2d2bd8dbf619598957777ff902c7268b7e18bb9547c1817536

Scanner detections:
12 / 68

Status:
Malware

Analysis date:
4/20/2024 12:38:57 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.2533978
7.11.122.216

avast!
Win32:Malware-gen
2014.9-140122

Bkav FE
W32.Clod146.Trojan
1.3.0.4613

Dr.Web
Trojan.Siggen4.32924
9.0.1.022

G Data
Win32.Trojan.Agent.UMCYJF
14.1.22

K7 AntiVirus
Riskware
13.174.10689

McAfee
Artemis!CE90408F5C98
5600.7243

NANO AntiVirus
Trojan.Win32.Siggen4.cisdnh
0.28.0.57029

Norman
Malware.AJDKQ
11.20140122

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14120

Sophos
PsKill
4.96

Trend Micro House Call
TROJ_GEN.R0CBOH0J613
7.2.22

File size:
3.6 MB (3,801,252 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\safe_v1_setup.exe

File PE Metadata
Compilation timestamp:
10/7/2005 11:05:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
98304:jhZbKi/uCXHkm7NbwHn7/DwlVr4RJaOWHTt35ni:jhd7BCn7/Du6yHTtJi

Entry address:
0x1000

Entry point:
E8, 9B, 27, 00, 00, 50, E8, A7, 22, 01, 00, 00, 00, 00, 00, 90, 55, 8B, EC, 53, 56, 57, 8B, 7D, 10, 8B, 5D, 0C, 8B, 75, 08, 8B, D3, FF, 75, 14, 68, E5, 40, 41, 00, 6A, 00, 6A, 00, 8B, C6, 8B, CF, E8, 26, 43, 00, 00, 81, EB, 10, 01, 00, 00, 74, 05, 4B, 74, 14, EB, 57, FF, 75, 14, 6A, 66, 56, E8, F8, 24, 01, 00, B8, 01, 00, 00, 00, EB, 47, 66, 81, E7, FF, FF, 66, FF, CF, 74, 07, 66, FF, CF, 74, 23, EB, 30, 68, 80, 00, 00, 00, 68, D4, 50, 41, 00, 6A, 65, 56, E8, 3E, 24, 01, 00, 6A, 01, 56, E8, 18, 24, 01, 00...
 
[+]

Entropy:
7.9531  (probably packed)

Code size:
76 KB (77,824 bytes)

The file safe_v1_setup.exe has been seen being distributed by the following URL.

Remove safe_v1_setup.exe - Powered by Reason Core Security