setup.exe

Installer

VerifiedInstallation

The application setup.exe by VerifiedInstallation has been detected as adware by 26 anti-malware scanners. The file has been seen being downloaded from safedownloadsrus130.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
VerifiedInstallation  (signed and verified)

Product:
Installer

Version:
1.0.0.1

MD5:
37aaa18ae1e5ed71555d30e00c1a7a57

SHA-1:
144030d1c4c57446256620b755d8968ceeffb7e5

SHA-256:
ea3441cb0480a395d54697dbb181285ec59c8de027871c8da4c0ac6ad5ecde5a

Scanner detections:
26 / 68

Status:
Adware

Analysis date:
5/7/2024 12:48:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.189304
364

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Generic
2015.05.17

Avira AntiVirus
W32/Neshta.a
7.11.30.172

avast!
Win32:Adware-gen [Adw]
2014.9-160206

AVG
AdGazelle
2017.0.2842

Bitdefender
Gen:Variant.Adware.Strictor.86912
1.0.20.185

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Adgazelle-32
0.98/20538

Dr.Web
Adware.Downware.11074
9.0.1.037

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.189304
8.16.02.06.08

ESET NOD32
Win32/AdGazelle.J potentially unwanted application
10.7.0.302.0

F-Prot
W32/S-6897f6c9
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
11.2016-06-02_7

G Data
Gen:Variant.Adware.Strictor.86912
16.2.25

IKARUS anti.virus
PUA.AdGazelle
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15794

Malwarebytes
PUP.Optional.Downware
v2016.02.06.08

MicroWorld eScan
Gen:Variant.Adware.Strictor.86912
17.0.0.111

NANO AntiVirus
Riskware.Win32.Downware.drcqse
0.30.24.1357

Norman
Gen:Variant.Adware.Strictor.86912
11.20160206

Panda Antivirus
Trj/Genetic.gen
16.02.06.08

Qihoo 360 Security
Win32/Virus.Adware.c16
1.0.0.1015

Reason Heuristics
PUP.AdGazelle.VerifiedInstallation.Installer (M)
16.2.6.8

Vba32 AntiVirus
AdWare.AdGazelle
3.12.26.4

VIPRE Antivirus
Threat.5063330
39676

File size:
276.1 KB (282,712 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/3/2015 3:42:42 PM

Valid to:
3/3/2016 3:42:42 PM

Subject:
CN=VerifiedInstallation, O=VerifiedInstallation, L=Las Vegas, S=Nevada, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00AD549677C65B0FD8

File PE Metadata
Compilation timestamp:
4/28/2015 7:12:25 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:NpsoyInSB3DBgfwSdg2Jk2BwiAO0AOVNC6tO:NOolnD3eT2BwiiLNU

Entry address:
0xFC73

Entry point:
E8, A6, AB, 00, 00, E9, 8B, FE, FF, FF, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 08, C3, 43, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, A8, 43, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 08, C3, 43, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03...
 
[+]

Entropy:
6.2460

Code size:
161 KB (164,864 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove setup.exe - Powered by Reason Core Security