setup.exe

The application setup.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.lpcloudbox402.com.
MD5:
14dc27c28ac78be84955e56ffe82fc07

SHA-1:
82cf5d9a8046688ef531ac655ad9f4003980fce4

SHA-256:
f4cf45bc21789dcdb1c7343a29ca81903d34700f06e697d45e1c5858965cdcba

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:47:31 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-CAH [PUP]
160121-0

AVG
Adware BundleApp_r.D
2015.0.4489

Kaspersky
not-a-virus:AdWare.Win32.AirAdInstaller
15.0.0.562

Sophos
Virus 'Mal/HckPk-A'
5.22

VIPRE Antivirus
Threat.4782985
46444

File size:
817.7 KB (837,344 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
4/3/2014 10:43:11 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:QgGScqZthc8IqUhl/82dbmTaLr68aKhONj7uF0s9hcoizSl+i71b37H2dJsmydVg:/5tadLm8+j7uDo/SbydaEBKvoIc77b

Entry address:
0x26BC30

Entry point:
EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, BE, BE, BE, BE, BE, BE, BE, BE, BE, BE, BE, BE, D4, D4, D4, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, EB, 9C, 9C, 9C, 6F, 6F, 6F, EB, EB, EB, EB, EB, EB, D4, D4, D4, C9, C9, C9, EB, EB, EB, EB, EB, EB, EB, EB...
 
[+]

Code size:
784 KB (802,816 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security