setup.exe

The application setup.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from d24p1vpeyzkq4h.cloudfront.net.
MD5:
63b0e502b1cc3527be87d3e4e7554998

SHA-1:
b4c5d96e4cbaea27e827aa9d733ba807125c8f97

SHA-256:
dd56bce6ccea4e6829080c85fc09fdacffaa1dbe0e12af9f6546ace9eb7b0021

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 2:48:27 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
160326-0

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.60
11.5.0.6191

ESET NOD32
Win32/DealPly.BU potentially unwanted application
8.0.319.0

Norman
Gen:Variant.Application.Bundler.60
10.04.2016 15:29:17

Reason Heuristics
PUP.NewMedia.ICDP (M)
16.5.14.12

File size:
694.5 KB (711,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:w6l5e5cz5277pN5277pp527j527LaA9ij5277E5277hTf:wk/agikTf

Entry address:
0xAA984

Entry point:
55, 8B, EC, 83, C4, F0, B8, 1C, A9, 4A, 00, E8, 4C, 9A, F5, FF, E8, 53, 7D, F5, FF, 3D, C1, 00, 00, 00, 0F, 85, D8, 00, 00, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 49, 98, 91, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 22, B5, 7C, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 49, 98, 91, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 49, 98, 91, 00, A7, 49, 7E, 00...
 
[+]

Entropy:
4.4083

Developed / compiled with:
Microsoft Visual C++

Code size:
679 KB (695,296 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security