setup-47555903.exe

Garden Variety Media

The application setup-47555903.exe by Garden Variety Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from files4.downloadtrunk116.com and multiple other hosts. While running, it connects to the Internet address 8c.3f.1632.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Garden Variety Media  (signed and verified)

Product:
Garden Variety Media

Version:
10.9.2.720

MD5:
3d6ff231a585d444e7e5df5f10aea109

SHA-1:
76667213965e7b73dfdd0f58fe11c2659bb8a606

SHA-256:
e48d36b5704115dae1ff4189c177d45c725d3038482751bc0c95d57b4ea1ae21

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:41:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DownloadAdmin.GardenVarietyMedia.Installer (M)
16.2.11.21

File size:
894.4 KB (915,888 bytes)

Product version:
10.9.2.720

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\setup-47555903.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
12/9/2015 1:52:38 AM

Valid to:
12/9/2016 1:52:38 AM

Subject:
CN=Garden Variety Media, O=Garden Variety Media, L="Oakland ", S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
093B7DDF075E0635

File PE Metadata
Compilation timestamp:
3/8/2015 1:16:57 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:/YMwiNRmchkR20bPsIU/fpvWkuasz8xz2WyAknYQ1WpSZaStcg5d1bUqST2JXC6D:/IiNEchkc0bkZfAV8xz2WyAknYQ1WpSJ

Entry address:
0x1066

Entry point:
E8, B5, D4, 00, 00, E9, DF, CC, 00, 00, FF, 25, 64, E5, 4B, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FF, 25, B4, EC, 4B, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, EC, 20, B9, 1E, 00, 00, 00, 8D, 04, 24, EB, 03, 8D, 49, 00, C6, 00, 00, 40, 83, E9, 01, 75, F7, 53, 55, 8B, 6C, 24, 2C, 56, 8B, C5, 57, 8D, 50, 01, 8A, 08, 40, 84, C9, 75, F9, 2B, C2, 8B, F8, 8D, 5F, 02, 53, FF, 15, 4C, 02, 41, 00, 83, C4, 04, 53, 8B, F0, 55, 56, FF, 15, 9C, 00, 41, 00, C6, 04, 3E, 00, C6, 44, 3E, 01, 00, 8D, 4C, 24, 10...
 
[+]

Entropy:
7.9649  (probably packed)

Code size:
57 KB (58,368 bytes)

The file setup-47555903.exe has been seen being distributed by the following 50 URLs.

http://files4.downloadtrunk116.com/dl-pure/1200645/.../?bc=1200645&checksum=88973995&cb=1577548163&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=77948869&cb=-1748149352&usefilename=true&executable=1200605

http://cdn1.drivereco.com/dl-pure/1200615/.../?bc=1200615&checksum=68723419&filename=Setup.exe&cb=-1211790223&usefilename=true&executable=1200605

http://cdn1.drivereco.com/dl-pure/1200615/.../?bc=1200615&checksum=48977893&filename=Setup.exe&cb=927503962&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=121385671&cb=-902310392&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200645/.../?bc=1200645&checksum=75085507&cb=139623398&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=59690243&cb=-1804359824&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=54911085&cb=-1103762808&usefilename=true&executable=1200605

http://cdn1.drivereco.com/dl-pure/1200615/.../?bc=1200615&checksum=56115411&filename=Setup.exe&cb=603030247&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=109525141&cb=-350627014&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=120248499&cb=2143193345&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200645/.../?bc=1200645&checksum=111522553&cb=1475491899&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200645/.../?bc=1200645&checksum=104851041&cb=1069689588&usefilename=true&executable=1200605

http://files4.downloadmanager103.com/dl-pure/1200647/.../?bc=1200647&checksum=48857121&filename=Super Mario World 2 - Yoshi's Island.exe&cb=-1032174402&usefilename=true&executable=1200605

http://cdn1.drivereco.com/dl-pure/1200615/.../?bc=1200615&checksum=50049663&filename=Setup.exe&cb=1711534680&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=50589871&cb=551515411&usefilename=true&executable=1200605

http://files4.filefly529.com/dl-pure/1200727/.../?bc=1200727&checksum=67718213&cb=-473158428&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200645/.../?bc=1200645&checksum=66279385&cb=-947436925&usefilename=true&executable=1200605

http://cdn1.drivereco.com/dl-pure/1200615/.../?bc=1200615&checksum=62740837&filename=Setup.exe&cb=753067093&usefilename=true&executable=1200605

http://files4.downloadtrunk116.com/dl-pure/1200643/.../?bc=1200643&checksum=77927289&cb=-1285798583&usefilename=true&executable=1200605

Latest 30 of 460 download URLs

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 8c.3f.1632.ip4.static.sl-reverse.com  (50.22.63.140:80)

Remove setup-47555903.exe - Powered by Reason Core Security