setup.exe

The application setup.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. The file has been seen being downloaded from d24p1vpeyzkq4h.cloudfront.net.
MD5:
ac2f8abd5520b65c9e46c5733456eeaa

SHA-1:
9f30c2ae471d18e66f5ac44685031caff5d3bee7

SHA-256:
1b2249f4609ccfb6be3adccd282f6bf1fce3eaace07114efa56c07fdaefefc48

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 2:59:32 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Symmi.55374
379

Agnitum Outpost
Trojan.Delphi
7.1.1

Avira AntiVirus
DR/Delphi.A.6338
8.3.2.2

Arcabit
Trojan.Adware.Symmi.DD84E
1.0.0.582

avast!
Win32:Malware-gen
2014.9-160121

AVG
DiCrypt
2017.0.2857

Baidu Antivirus
PUA.Win32.DealPly
4.0.3.16121

Bitdefender
Gen:Variant.Adware.Symmi.55374
1.0.20.105

Emsisoft Anti-Malware
Gen:Variant.Adware.Symmi.55374
8.16.01.21.06

ESET NOD32
Win32/DealPly.BU potentially unwanted (variant)
10.12402

F-Prot
W32/DealPly.C.gen
v6.4.7.1.166

G Data
Gen:Variant.Adware.Symmi.55374
16.1.25

IKARUS anti.virus
Dropper.Delphi
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.210.17525

McAfee
RDN/Generic PUP.z
5600.6513

MicroWorld eScan
Gen:Variant.Adware.Symmi.55374
17.0.0.63

Panda Antivirus
Trj/CI.A
16.01.21.06

Trend Micro
TROJ_GEN.R01TC0OHP15
10.465.21

VIPRE Antivirus
Trojan.Win32.Generic
44520

File size:
227.5 KB (232,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:9HHtpIsWuPZr51RoXRoMQcxqmHWjmaFRU8GiRU8GrPf7R0QShtWEVz/EG:9TWuPZzReRD/omPaFCtiCtfRyDW0B

Entry address:
0x313B0

Entry point:
55, 8B, EC, 83, C4, F0, B8, 50, 13, 43, 00, E8, F0, 36, FD, FF, E8, 27, 13, FD, FF, 3D, C1, 00, 00, 00, 0F, 85, D8, 00, 00, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 49, 98, 91, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 22, B5, 7C, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 49, 98, 91, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 49, 98, 91, 00, A7, 49, 7E, 00...
 
[+]

Entropy:
6.0359

Developed / compiled with:
Microsoft Visual C++

Code size:
193.5 KB (198,144 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security