setup.exe

TOV KOMSERV UKRAYINA

The application setup.exe by TOV KOMSERV UKRAYINA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from dl.appsdesktop.com.
Publisher:
TOV KOMSERV UKRAYINA  (signed and verified)

MD5:
a804b8c9f0fb656afa69918f2d5de9a7

SHA-1:
5b1944c498ba2d7d67483818cea18f090064b115

SHA-256:
57ee5a3cc6fbcecfa5e94eaf961d7b6966247c6fd9b2ab139702815e53bfde78

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/27/2024 1:12:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse (M)
16.7.30.9

File size:
581.1 KB (595,064 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/23/2014 2:00:00 AM

Valid to:
12/24/2015 1:59:59 AM

Subject:
CN=TOV KOMSERV UKRAYINA, O=TOV KOMSERV UKRAYINA, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
293DA2C0D82B35ED08F0011D51ECDA8C

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:YvEZVXqb7dG20irxpVO9pJ5lcK+LiDCPiggsHN04:YIVZzirfVas8CFLl

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9742

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security