setup.exe

Bohr­-ium Group

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application setup.exe by Bohr­-ium Group has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from dl.loadclientinputsrv.com. It is part of the Brightcircle group of web-extensions that inject advertisements in the browser.
Publisher:
Bohr­-ium Group  (signed and verified)

Description:
Dyeozjnqrq

Version:
8.0.9.1

MD5:
5e553897ccd6acb7846c478acdac0026

SHA-1:
7c3034294fee3b4f0a42018068511877ab4d6b0d

SHA-256:
1b17774c173486aca76a5a2e0039501fe2e2c557cb5570200082bd6eda874175

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/19/2024 1:56:49 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3368

Kaspersky
not-a-virus:HEUR:AdWare.NSIS.Adwapper
15.0.0.494

Panda Antivirus
Trj/Chgt.E
14.08.28.11

Reason Heuristics
PUP.Installer.BohriumGroup.F
14.8.28.22

File size:
8.5 MB (8,952,632 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/13/2014 7:00:00 PM

Valid to:
8/14/2015 6:59:59 PM

Subject:
CN=Bohr­-ium Group, O=Bohr­-ium Group, STREET=Athinodorou 3, L=Nicosia, S=Nicosia, PostalCode=2025, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
79AE90FF01AB303C263027AB2FC84409

File PE Metadata
Compilation timestamp:
12/4/2012 7:54:38 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
196608:hMcMl/7iB3FelGqPc0R09UjQ64HIV1fJkZBxT4E5cEEeAVD2vQioP:hMrFOTelRE9nG1mZvT95EeE6o

Entry address:
0x4101

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, B3, 7C, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, B4, 7C, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, B4, 7C, 00, 56, A3, 6C, 23, 7C, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, C8, 23, 7C, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, B4, 7C, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Entropy:
7.9986  (probably packed)

Code size:
32.5 KB (33,280 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security