setup.exe

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application setup.exe by Pinball has been detected as adware by 31 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from a.abundance27.com and multiple other hosts.
Publisher:
Pinball Corporation.  (signed and verified)

Description:
Installer

Version:
2.0.690.2

MD5:
6fc1e2dab4bf9b0f73c121adbf5d2109

SHA-1:
644b13ea8aff53e4926e2f5b27d5c7f31dab6579

SHA-256:
e58a10a721481b610221a1b2d38ca2ea27723fc6b2797337bc51520b89819cb6

Scanner detections:
31 / 68

Status:
Adware

Analysis date:
5/18/2024 6:29:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Hotbar.1
949

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2014.07.01

Avira AntiVirus
ADSPY/AdSpy.Gen2
7.11.30.172

avast!
Win32:HotBar-CJ [PUP]
140617-1

AVG
Adware Skodna.Generic_r.BO
2014.0.3986

Bitdefender
Gen:Variant.Adware.Hotbar.1
1.0.20.905

Clam AntiVirus
Suspect.W32.AdInstall.PBCXP
0.98/19073

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18721

Dr.Web
Adware.Hotbar.700
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Hotbar
8.14.06.30.08

ESET NOD32
Win32/Adware.HotBar.K application
7.0.302.0

F-Prot
W32/HotBar.R.gen
4.6.5.141

F-Secure
Gen:Variant.Adware.Hotbar.1
11.2014-30-06_2

G Data
Gen:Variant.Adware.Hotbar
14.6.24

IKARUS anti.virus
not-a-virus:AdWare.Win32
t3scan.1.6.1.0

Kaspersky
not-a-virus:HEUR:WebToolbar.Win32.Zango
14.0.0.3631

McAfee
Adware-HotBar.f
5600.7083

MicroWorld eScan
Gen:Variant.Adware.Hotbar.1
15.0.0.543

NANO AntiVirus
Trojan.Win32.Gen4.brmplv
0.28.0.60577

Norman
Pinball.A
11.20140630

Qihoo 360 Security
Malware.QVM11.Gen
1.0.0.1015

Quick Heal
Adware.Rugo.A
6.14.14.00

Reason Heuristics
PUP.Installer.PinballCorporation.F
14.8.8.0

Rising Antivirus
PE:Adware.HotBar!1.6AAD
23.00.65.14628

Sophos
ClickPotato Installer
4.98

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11031

Trend Micro
HeurSpy_Zango-3
10.465.30

Vba32 AntiVirus
AdWare.ScreenSaver
3.12.26.3

VIPRE Antivirus
Threat.4672643
29708

Zillya! Antivirus
Adware.ScreenSaver.Win32.2160
2.0.0.1843

File size:
226.2 KB (231,608 bytes)

Product version:
2.0.690.2

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/21/2013 6:00:00 PM

Valid to:
6/21/2014 5:59:59 PM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D1DC2902C5A9A3F990FBAA1F9239EE0

File PE Metadata
Compilation timestamp:
2/22/2013 10:13:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:pWrHYy0ygE1cENGKynaAU27w+a1SCobPzxeEkhQeJTtxtpp0bbV:pWrHYwOENry7bCobPNqtxjp0bbV

Entry address:
0x88410

Entry point:
60, BE, 00, 30, 45, 00, 8D, BE, 00, E0, FA, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8843

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
216 KB (221,184 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security