setup.exe

Acute Angle Solutions Ltd.

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Acute Angle Solutions has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d423.bluequezal.com.
Publisher:
Acute Angle Solutions Ltd.  (signed and verified)

MD5:
ed089fa31a7f58b8b5202782997355d0

SHA-1:
a1a101ed64b3cbc2f574998a44a2aeccbef9ae09

SHA-256:
38eaa7e84cb2d5516a25770fa820deebe60408e55043c3117b03b976e2b8f5ef

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/25/2024 11:23:01 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Acute
2015.0.3279

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.141126

ESET NOD32
MSIL/Adware.PullUpdate
8.10554

G Data
Win32.Adware.AcuteAngle
14.11.24

K7 AntiVirus
Adware
13.183.13642

Malwarebytes
PUP.Optional.Disasteroids.A
v2014.11.26.07

McAfee
Artemis!211634C4A203
5600.6935

Reason Heuristics
PUP.Installer.AcuteAngleSolutions.F
14.11.26.7

Sophos
Pull Update
4.98

VIPRE Antivirus
Injekt
33880

File size:
4 MB (4,211,544 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/30/2014 4:00:00 PM

Valid to:
1/31/2015 3:59:59 PM

Subject:
CN=Acute Angle Solutions Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Acute Angle Solutions Ltd., L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0A7A77148C6F7A33F9174DA187F6FEF0

File PE Metadata
Compilation timestamp:
6/6/2009 2:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:uDBpzuNM2jv43DLxNWtocgolxdzBlkafcoaUphlDpzuNM2jv43T:uDuNMSDzBaaEopTsNMS4

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9820

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following URL.

http://d423.bluequezal.com/dst/.../Setup.exe

Remove setup.exe - Powered by Reason Core Security