setup.exe

Beamrise

SIEN S.A.

This is the SIEN AppScion Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by SIEN S.A has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
The Beamrise Authors  (signed by SIEN S.A.)

Product:
Beamrise

Version:
3.27.0.5541

MD5:
4d54954474d35bf8fe98289e5824657d

SHA-1:
adc521b2b610e95bd1bd59f1a81077aad16e1877

SHA-256:
b1d57e9dee7cf8947323bc29535d1d7ec1e86af161a766e9e59ca9a7c183d715

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 2:31:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.SIENSA.Bundler (M)
16.2.11.4

File size:
1.1 MB (1,151,808 bytes)

Product version:
3.27.0.5541

Copyright:
Copyright 2013 The Beamrise Authors. All rights reserved.

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\beamrise\application\3.27.0.5541\installer\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2012 9:00:00 PM

Valid to:
8/22/2014 8:59:59 PM

Subject:
CN=SIEN S.A., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SIEN S.A., L=Paris, S=France, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
514EA00D30C8C244C3E818890BF73967

File PE Metadata
Compilation timestamp:
7/25/2013 10:43:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:HyBOhtLSP9c44U0ZviAXszQFJJXQW8TpYs2u1:HyBOhIP9ZiZKAXTp8msV1

Entry address:
0x85843

Entry point:
E8, AA, 97, 00, 00, E9, 89, FE, FF, FF, 6A, 68, 68, 40, 10, 4C, 00, E8, A7, 9A, 00, 00, 8B, 7D, 08, 89, 7D, 94, 8B, 75, 0C, 33, DB, 89, 5D, 9C, 33, C0, 3B, F3, 0F, 95, C0, 3B, C3, 75, 1F, E8, 39, 39, 00, 00, 89, 18, E8, 1F, 39, 00, 00, C7, 00, 16, 00, 00, 00, E8, 80, F1, FF, FF, 83, C8, FF, E9, 9C, 00, 00, 00, 6A, 30, 53, 56, E8, 36, F9, FF, FF, 83, C4, 0C, 83, FF, FE, 75, 14, E8, 09, 39, 00, 00, 89, 18, E8, EF, 38, 00, 00, C7, 00, 09, 00, 00, 00, EB, D3, 3B, FB, 7C, 08, 3B, 3D, 28, A3, 4C, 00, 72, 14, E8...
 
[+]

Code size:
654 KB (669,696 bytes)

Remove setup.exe - Powered by Reason Core Security