setup.exe

Stepitapp LLC

The application setup.exe by Stepitapp has been detected as adware by 9 anti-malware scanners. The file has been seen being downloaded from www.mydownloadhome.com and multiple other hosts.
Publisher:
Stepitapp LLC  (signed and verified)

MD5:
98ec4676e97b3c6c4e2fe80cada4f289

SHA-1:
618e60264a901f34d08ac5dcd6b9f78955c7957f

SHA-256:
a611369d9f8ca91720b5d2afe7c9cb8720ee3011e15e39c8f54594a2d0a3de66

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
6/26/2025 2:00:31 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dldr.Agent.216048
7.11.201.138

avast!
Win32:Dropper-gen [Drp]
2014.9-150129

ESET NOD32
Win32/Downloader.Agent.AI (variant)
9.11021

McAfee
Artemis!F4CD8201B97A
5600.6871

Reason Heuristics
PUP.Installer.Stepitapp.F
14.12.22.11

Sophos
Generic PUA OF
4.98

Trend Micro House Call
Suspicious_GEN.F47V1213
7.2.29

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
36688

File size:
211 KB (216,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/11/2013 12:00:00 AM

Valid to:
12/11/2014 11:59:59 PM

Subject:
CN=Stepitapp LLC, O=Stepitapp LLC, POBox=1252, STREET=9 W. 31st Street, L=Bayonne, S=New Jersey, PostalCode=07002, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EA7DEF51F4F715C2C81433CCD6B15766

File PE Metadata
Compilation timestamp:
12/11/2014 10:09:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:Dbm6l7b9RZtLiNZsWFel4UDP5i/7VgmpW7+oJ0y8FIPCgHRwa:Db7l7b9zt+No4G5+Vg6W7+oJmIP1n

Entry address:
0x145C1

Entry point:
E8, CA, 6B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 14, 75, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, A4, 70, 42, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81...
 
[+]

Entropy:
6.3972

Code size:
151 KB (154,624 bytes)

The file setup.exe has been seen being distributed by the following 16 URLs.

http://www.mydownloadhome.com/.../2?sub_id=0lr02r7pnvvgJ08Y_ZD-cWr4tvWsWFyIvbmzDo2eE3VFI68Sw-DF-SZJBrW17KYSKFrcIGvIZBeX5dIAEbH1NSy_XWWt9VAUbDEWzlr0CYDc_Xxn5-Or6n0As9ei8ySqNVofCKCt0YdCpvaDlMfC0ZCYK4vxdNCL7y0Ip0ScUu84bKxpEMDF25c9-twEMYkuv5E6dSW43TjwCUz6SqmJgvljh5LqJi48LaKG143y4UDgbjD7laV3Gv-mOyrZvuwKRp1mzPiMFoMkzACtGd-xtN0TRir-2DV8Z2UsdKZYKH6YW8kYncz6HmYRNAlWfN6SuklsQwYEA0wiHOPG2A3RXm-lepAKhC_Y1TSXxjuHSqxxW_uwfxJs5ecP-PSxSukPoyhVTGPmfdUXW6css7Vd3-pgenY-Vg-ObLh7LCPdIJf3UXBVwDvGyWxDhSqqYOqMZHDokXY&pub_id=88&template=lp

http://www.downanapp.com/.../300?sub_id=adk2_UfrB95bjYic7vKs2DTIZ0VSxj99z7u1zW5NbMm6QDLFdYKiLNHbfW7Bkt5H2kztkWv24IJt7QqINrSymOTD8dJgTxylOvZx5UC2aTt_lHNCptElxY_Aj357S7KiuVon9q1UoHXto0fiLqznVzIp3wFdlvQliBmuQ-iGgtzhwMTX6qJsqC3Y4MkD6_3E36Q-4N1cy1UMGuoVrn1MRVpVUQV-tVdqGqoy21s-Pvug_FGzc_3uSifzrZC53-9BClxmb0RtqJmDjUrrdbkZ721zfkw2WrLP5-AMOdlDknsuELLUnIo2BJqyiT-eRR6EAnPJKvxY8krgmyQMCrBXIKPR1kcEdak268xVqFsaC31vuzXwcC-SMMMrUakz4dbnUalK5xtbtXdrWdERIc-xEOY4Tg59i-C2pqx7KXy-UO9Esxw&pub_id=334&template=lp4

http://www.downanapp.com/.../300?sub_id=adk2_5-DUA2ze41BQe5oDsLF0kEjxETzU1Lt5J6gh2LyaZk-jhAXNhrNa1bDQtjWHxa_lxU_o_TVWSUXOO5gLNttuMfO1c7M29jjpFC5OLMbgqjjF9nvr8y8A1yfvn1tuetweiENU7HCzZLNh0l9RSkto3ZZ7ru9-aedR8g5UiaA-18P4SLuv_3Kwxp2XsuMygfL9cACesnBPeL4kGsIZ1PRMG_V70yhpXVHqL66aTdWDhzr94gFlgxlBIrj8uYw9MiXl5dX3EdoqvbUEfWNHZBOES6mCys0QxCWqlg61RhL_jShxb8jDNCMGSnC2XKc6cMepeMv5QXCVlB7HzduLWxOIJvOFNjfVpmPAj7ZgM4TrEyUfrvzGNCSNs5ECcjJgtkPTvt9tm-eUh3eW8lQ4L2eqKc-3CoX1leOWbHjwGWyffo-FV2y4IAloFuqZeKf_aPHi&pub_id=334&template=lp4

http://www.downanapp.com/.../300?sub_id=adk2_Nj3CnGOXGdeP2sHm2eVPlQhsXhQAGrS7T36qF0KfslJcLmQiDDzIUf94WOwRU7Gyh7KNwBX1zVWLxnzQVGRQd-u3l9-zON6PMkiMXhzZRvaNIRpcYSKVcWDQTtJmmhbihm86mex2MJMeNaV2vE_Re_RT22Ah2kYypY1zU0MuZOWG4N8nFbA_saWozYIjmKUh_yylACEOVHQpY9KZuxUQEa-vPp5aAKBHwW60f3mhzN8xDC_d5d90OGrbqhLgrTJLUsNTPxAPJhobGhtupWb_V_mJm5Sh1B3AqfyqOJjdEzY28ysYA1VxPmXRdeqJPgtZD7ZU-8U99n2coAuKl6J5CEkqVGCqNe5yyo3eQSwKpK1OPJzPsnP42P17tD3BC5AjoRwESu4mVxqpCyQ8iIRK_6osnS8wHmAcidUqNPK2To_tJK8G7T4cpgr8WJoibw&pub_id=334&template=lp4

Remove setup.exe - Powered by Reason Core Security