setup.exe

Digital Plugin SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Digital Plugin SL has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Digital Plugin SL  (signed and verified)

MD5:
fbde286c62eaba1f2aeecc67b6e0a04c

SHA-1:
1782ba606f107d36e96309e2e687bd982e3e4cdc

SHA-256:
49f8bbcc8e117205507c723c8a5ed1ab6b02fac341d27117511753902ec556bd

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Bundle or install adware offers through a modified download manager or installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/5/2024 12:50:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Graftor.182456
5639178

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.06.04

Arcabit
Trojan.Application.Graftor.D2C8B8
1.0.0.425

AVG
Generic
2016.0.3089

Bitdefender
Gen:Variant.Application.Graftor.182456
1.0.20.770

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.252
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Graftor.182456
10.0.0.5366

ESET NOD32
Win32/SoftPulse.AG potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Graftor
5.14.151

G Data
Gen:Variant.Application.Graftor.182456
15.6.25

K7 AntiVirus
Unwanted-Program
13.204.16128

Malwarebytes
PUP.Optional.DomalIQ.SID.A
v2015.06.03.04

MicroWorld eScan
Gen:Variant.Application.Graftor.182456
16.0.0.462

NANO AntiVirus
Trojan.Win32.Domaiq.dsloug
0.30.24.1636

Norman
Gen:Variant.Application.Graftor.182456
02.06.2015 14:23:46

Quick Heal
PUA.Digitalplu7.Gen
6.15.14.00

Reason Heuristics
PUP.Softpulse.Bundler
15.6.3.16

VIPRE Antivirus
Threat.4783235
40786

File size:
563.9 KB (577,440 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/26/2014 1:00:00 AM

Valid to:
9/27/2015 12:59:59 AM

Subject:
CN=Digital Plugin SL, O=Digital Plugin SL, L=Guia de Isora, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
63B78976E4F16AA4AC250388162DD349

File PE Metadata
Compilation timestamp:
6/1/2015 3:37:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:V9CYh4DPlf3e42zj7OP/cIilnAT6s9OoX3JqkCPlkHQF0H5xA3txBwtxlHC:WMO24jcIQnAOs9bXZHQFyzgtbw4

Entry address:
0x1000

Entry point:
B8, D4, CC, 5C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 0A, 54, E6, 2B, 19, 27, 7C, 0A, C0, 66, 4E, 8A, 35, 05, 5F, 48, EB, D8, 87, 74, 62, 2E, 07, AB, CF, 46, 98, F9, A7, E7, 81, 57, BC, 6D, E1, D2, 86, 21, D4, 5D, 2E, 66, EB, 05, C6, D0, 83, B7, DE, 83, 1B, 00, 5E, 20, 6C, 2F, F8, F2, C7, CC, 94, 16, 19, 51, 80, A8, 99, 9D, 12, C2, 8D, A5, EE, E3, 84, EE, 5B, C8, 8B, C8, 7A, 85, 71, 93, 9F, 23, 63, 01, 7B, F5, 38, B8, C3...
 
[+]

Packer / compiler:
PECompact v2

Code size:
1.2 MB (1,242,112 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to lga25s40-in-f200.1e100.net  (216.58.219.200:443)

TCP (HTTP):
Connects to ec2-52-26-254-39.us-west-2.compute.amazonaws.com  (52.26.254.39:80)

TCP (HTTP):

TCP (HTTP):
Connects to a23-13-165-163.deploy.static.akamaitechnologies.com  (23.13.165.163:80)

Remove setup.exe - Powered by Reason Core Security