Setup.exe

Installer Internet

Software generic

The file Setup.exe, “Installer Internet Setup ” has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Software generic

Product:
Installer Internet

Description:
Installer Internet Setup

Version:
1.6.2.5

MD5:
7eae189536dce09577245035b21e8cf5

SHA-1:
a05db2ca3c05a9da0731a8cfefe078ff443b7045

SHA-256:
ae3e654bc3a5cf762414439c38da5590d05d707334fc3d7a88df74ca0dccf772

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 8:44:57 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2015.06.20

ESET NOD32
Win32/InstallCore.YL potentially unwanted application
7.0.302.0

G Data
Win32.Application.InstallCore.EG
15.6.25

Malwarebytes
v2015.06.19.02

NANO AntiVirus
Riskware.Win32.InstallCore.dsmvwm
0.30.24.2086

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

VIPRE Antivirus
Threat.4788237
41244

File size:
765.7 KB (784,039 bytes)

Product version:
3.1.1

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:As0GNGbUrYMp3q4mvUcWStVVwCYtvGn2J6z+cV4+qDI0TMmQP2adR5OG6pwZhxUE:As0sGbCdcvUcRrwCYtgCUbqDxnW/2wbX

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8741

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to s3-1.amazonaws.com  (54.231.2.224:80)

TCP (HTTP):
Connects to ec2-54-243-153-163.compute-1.amazonaws.com  (54.243.153.163:80)

TCP (HTTP):
Connects to ec2-52-10-224-155.us-west-2.compute.amazonaws.com  (52.10.224.155:80)

Remove Setup.exe - Powered by Reason Core Security