setup.exe

The executable setup.exe has been detected as malware by 1 anti-virus scanner. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from cdn.pmdownloadcdn.com.
MD5:
299c8ee3eb39b3a1cc6d875e431658d5

SHA-1:
7960e79fc7952584bd24ec7a3f317170256f7ec3

SHA-256:
050bb22807ed5cd1bb89a86903146cfda557f791df77122800018b278f1c8ef3

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
5/10/2024 4:42:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
(M)
16.6.7.0

File size:
536 KB (548,872 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12288:YcMqMTKFYxR1IQXCoChfkhM0Q/VL4GNroP+C/kZyamP12KLHqSv:xw3Cihc9LLooZM12KLHqSv

Entry point:
0B, F6, BB, F9, B7, 90, FF, C1, C0, B2, C2, D6, AB, 06, 92, FC, CA, AD, 4C, 50, 9A, 27, 93, 5F, 76, 0F, 63, B8, F3, 22, 31, 25, 77, 53, 34, E7, D0, E3, D8, 90, CF, BE, 78, 4D, 4C, 95, C8, CB, FF, 6F, B2, 0D, 19, B8, 71, C9, 8F, F8, 35, 31, 74, C2, A6, 3F, E6, 88, FF, E4, 5D, 55, A2, AE, 6A, AB, 61, C8, 28, 00, D3, 76, FA, 91, 79, 52, 58, 93, 83, 03, B3, ED, 7F, 37, CF, 06, 43, 00, 03, 5C, D7, F2, 4A, E5, 31, 9F, 12, 68, 03, 4C, 31, 5D, 05, F3, 73, 30, 5B, 69, A0, 11, 04, 02, 03, 04, 09, 06, 07, 08, 30, F5...
 
[+]

Entropy:
7.6990

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security