setup.exe

The application setup.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.lpcloudbox402.com.
MD5:
605a9c1c2ff0e34ea70d0a495e3e6491

SHA-1:
821e6d73167c04c3d6b52cc831f72f4a0cd93a36

SHA-256:
cf9ef4d740b11f1fc312db3145e37b057f16f19c9b3a875c0ddd3256b2e4ca2a

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:30:26 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-CAH [PUP]
160118-1

AVG
Adware BundleApp_r.D
2015.0.4489

Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
15.0.0.562

Sophos
Virus 'Mal/HckPk-A'
5.23

File size:
817.7 KB (837,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
4/3/2014 10:43:11 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:QgGSOqZthclIqRhl/82dbt5aLr4ajhmNj7uL0s9hcolBeD+i71b34JCsmydV4EDF:/5KBGLMpj7upoqeZwsEDKvoIc76I

Entry address:
0x26BC30

Entry point:
EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF, EF...
 
[+]

Code size:
784 KB (802,816 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security