setup.exe

Moozy

Conversionads

The application setup.exe, “Moozy Setup ” by Conversionads has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from moozymusic.com.
Publisher:
Conversionads  (signed and verified)

Product:
Moozy

Description:
Moozy Setup

MD5:
530f6d15bdb72d51c0e261c8e046063b

SHA-1:
39f683febab4de915dadccbc9bad8208f6bbfd49

SHA-256:
169c26ce4a5a64b0d41293d0ee4059358f3561bbc2ad3a07607af89970f9dcbd

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
4/24/2024 7:28:36 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Agent.NMP
7.11.105.176

avast!
Win32:AddLyrics-A [Adw]
2014.9-151118

AVG
Agent.F
2016.0.2922

Comodo Security
ApplicUnwnt
17040

Dr.Web
Adware.Zugo.71
9.0.1.0322

Emsisoft Anti-Malware
Virus.Win32.Heur!IK
8.15.11.18.03

ESET NOD32
Win32/Toolbar.Zugo
9.10317

Fortinet FortiGate
W32/Toolbar.ZUGO
11/18/2015

F-Prot
W32/SuspPack.D.gen
v6.4.6.5.141

F-Secure
Adware.Agent.NMP
11.2015-18-11_4

IKARUS anti.virus
Virus.Win32.Heur
t3scan.1.1.107.0

K7 AntiVirus
Riskware
13.120.5775

McAfee
Artemis!3B1832F23E25
5600.6578

MicroWorld eScan
Adware.Agent.NMP
16.0.0.966

NANO AntiVirus
Riskware.Win32.SearchAssistant.clxqh
0.26.0.55203

Reason Heuristics
PUP.Conversionads.Installer (M)
15.11.18.3

Sophos
Conversion Ads
4.93

Trend Micro House Call
ADW_ZUGO
7.2.322

Trend Micro
ADW_ZUGO
10.465.18

Vba32 AntiVirus
AdWare.SearchAssistant
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
11005

File size:
1.5 MB (1,547,752 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
6/5/2011 6:00:00 PM

Valid to:
6/5/2012 5:59:59 PM

Subject:
CN=Conversionads, O=Conversionads, STREET=Am Weinberg 5, L=Neubeuern, S=Neubeuern, PostalCode=83115, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00C774EE3B8DAE0D50741CD0F860CE601C

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:G3FaxViKvQy+WwHZGelIsegsT4ZHXQ7p8tG+4qpF+lillTg05y4Xh7vJReZvuU8j:GgxXIy+JGyklT4NXQ7pkBpggRgaRXh73

Entry address:
0x9C18

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, AE, 94, FF, FF, E8, B5, A6, FF, FF, E8, 44, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, D4, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 9D, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 5A, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9893

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security