setup.exe

Big Bulb Ideas IT Pvt Ltd

The application setup.exe by Big Bulb Ideas IT Pvt has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from unipackdlzone.com.
Publisher:
Big Bulb Ideas IT Pvt Ltd  (signed and verified)

MD5:
e2e86be3c8d065a304371d2e85ee4187

SHA-1:
830d0b74ea7de653dc53a6a57e59331febcbd8ae

SHA-256:
abc508960d25d019d7a2e9fef8980dedd770839ad092c6d9407c90741d766092

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/26/2024 2:10:54 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
Win.Trojan.Lmir-1366
0.98/21511

Dr.Web
Adware.Downware.1551
9.0.1.0202

Reason Heuristics
PUP.BigBulbIdeasITPvt.Installer (M)
15.7.21.2

File size:
1.6 MB (1,706,560 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
10/31/2012 10:39:25 PM

Valid to:
10/23/2013 5:49:14 PM

Subject:
CN=Big Bulb Ideas IT Pvt Ltd, O=Big Bulb Ideas IT Pvt Ltd, L=Secunderabad, S=Andhra Pradesh, C=IN

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4F23C3D665B751

File PE Metadata
Compilation timestamp:
12/6/2009 8:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:mPFGpRe9P5aSrKtTuIFP5gZibgghPmeAP0rVObfI0S6KkHJbSUy8aPhxij233u8p:mPIre9Pc2U9B2JgsBg2pbVaiae8/k4

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9722

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

http://unipackdlzone.com/.../PoolSetup_Wrapper.exe

Remove setup.exe - Powered by Reason Core Security