setup.exe

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application setup.exe by Pinball has been detected as adware by 32 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from b.juiceknowledge.com.
Publisher:
Pinball Corporation.  (signed and verified)

Description:
Installer

Version:
2.0.690.2

MD5:
94e64c0519a9e021ccc6d5ee914ca7a9

SHA-1:
4ce99fa2af7125d3cddb82a4fec192176122f614

SHA-256:
6b7f0f7b2537091efabc237618e3b7cda9527d4e903bd35f3949ed1462f9efa7

Scanner detections:
32 / 68

Status:
Adware

Analysis date:
4/19/2024 1:02:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Hotbar.1
875

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2014.09.13

Avira AntiVirus
ADSPY/AdSpy.Gen2
7.11.30.172

avast!
Win32:HotBar-CJ [PUP]
140908-2

AVG
Adware Skodna.Generic_r.BO
2014.0.4015

Bitdefender
Gen:Variant.Adware.Hotbar.1
1.0.20.1275

Clam AntiVirus
Suspect.W32.AdInstall.PBCXP
0.98/19357

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
19498

Dr.Web
Adware.Hotbar.700
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Hotbar
14.09.12

ESET NOD32
Win32/Adware.HotBar.K application
7.0.302.0

F-Prot
W32/HotBar.R.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Hotbar.1
11.2014-12-09_6

G Data
Gen:Variant.Adware.Hotbar
14.9.24

IKARUS anti.virus
not-a-virus:AdWare.Win32
t3scan.1.7.8.0

Kaspersky
not-a-virus:HEUR:WebToolbar.Win32.Zango
14.0.0.3261

McAfee
Adware-HotBar.f
5600.7009

MicroWorld eScan
Gen:Variant.Adware.Hotbar.1
15.0.0.765

NANO AntiVirus
Trojan.Win32.Gen4.brmplv
0.28.2.61942

Norman
Pinball.A
11.20140912

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Adware.Rugo.A
9.14.14.00

Reason Heuristics
PUP.Installer.PinballCorporation.F
14.9.12.20

Rising Antivirus
PE:Adware.HotBar!1.6AAD
23.00.65.14910

Sophos
ClickPotato Installer
4.98

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11177

Trend Micro House Call
HeurSpy_Zango-3
7.2.255

Trend Micro
HeurSpy_Zango-3
10.465.12

Vba32 AntiVirus
AdWare.ScreenSaver
3.12.26.3

VIPRE Antivirus
Threat.4672643
32938

Zillya! Antivirus
Adware.ScreenSaver.Win32.2160
2.0.0.1920

File size:
233.2 KB (238,776 bytes)

Product version:
2.0.690.2

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/22/2013 3:00:00 AM

Valid to:
6/22/2014 2:59:59 AM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D1DC2902C5A9A3F990FBAA1F9239EE0

File PE Metadata
Compilation timestamp:
2/22/2013 8:13:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:LWrHYy0ygE1cENGKynaAU27w+a1SCobPzxeEkhQeJzvebUiPh34:LWrHYwOENry7bCobPN42bUKh34

Entry address:
0x8A180

Entry point:
60, BE, 00, 30, 45, 00, 8D, BE, 00, E0, FA, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8878

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
224 KB (229,376 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security