setup.exe

The application setup.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from d24p1vpeyzkq4h.cloudfront.net.
MD5:
19af7e77d3e3da551f1db6cdbe2ebd66

SHA-1:
24c215542f12cbd4edc9c0f6341fd725953542a3

SHA-256:
09105df1b32f9b9f0d033fd3b4bcbb808e78211a3f81c5e72e78dd9c38d7718b

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 12:23:45 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
150717-0

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.60
11.5.0.6191

ESET NOD32
Win32/DealPly.BX potentially unwanted application
8.0.319.0

Norman
Gen:Variant.Application.Bundler.60
10.04.2016 15:29:17

Reason Heuristics
PUP.NewMedia.ICDP (M)
16.4.11.6

File size:
1 MB (1,095,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:2NlvMSlvMxwlDlCFolvMftx6cDColvMftx6cDCAlvMftxQlvMftxvgl2XblvMftt:2YnFRDCRDCZL+3yu

Entry address:
0x106070

Entry point:
55, 8B, EC, 83, C4, F0, B8, 08, 60, 50, 00, E8, 60, E3, EF, FF, E8, 67, C6, EF, FF, 3D, C1, 00, 00, 00, 0F, 85, D8, 00, 00, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 49, 98, 91, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 22, B5, 7C, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 49, 98, 91, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 49, 98, 91, 00, A7, 49, 7E, 00...
 
[+]

Entropy:
4.3281

Developed / compiled with:
Microsoft Visual C++

Code size:
1 MB (1,069,568 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security