setup.exe

The application setup.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www.lpcloudsvr407.com.
MD5:
f7591bf648299fbf8c8d38fa2a0bc0ac

SHA-1:
777dc1864b827ccf4f9a35e08a5c8ea6eab84155

SHA-256:
82f42f714641f907aedabbcc27cf19cf0dbc2af9605707afa95d011ab5d8301f

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:00:48 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware AdPlugin.DAO
2015.0.4568

Emsisoft Anti-Malware
Application.Bundler.GL
11.5.0.6191

F-Secure
Riskware.Application.Bundler.GL
5.15.96

Norman
Application.Bundler.GL
19.05.2016 05:17:13

File size:
335.8 KB (343,831 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
10/28/2014 3:47:36 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:4clplmpqjhAUlAVBUHKpi/ghUlsdZt/VZNwU8htyjuZisqpNRsYhg:3lplmpmHAVBVg/8ZXGyWisqaYhg

Entry address:
0xEE6C0

Entry point:
60, BE, 00, B0, 49, 00, 8D, BE, 00, 60, F6, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.9017

Packer / compiler:
UPX 2.90LZMA

Code size:
336 KB (344,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security