setup.exe

The executable setup.exe has been detected as malware by 13 anti-virus scanners. The file has been seen being downloaded from d24p1vpeyzkq4h.cloudfront.net.
MD5:
8c561d03ccba1da007c4bd0760d13375

SHA-1:
b764262c9c29a5d53523cd348e7158c19ad10ac1

SHA-256:
284b380b5aba1f330cbedeb5ed0aec92a90a0140c2c48f8ce5b835e20bb07e73

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
4/29/2024 9:29:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2781113
385

Avira AntiVirus
TR/Rogue.118784.149
8.3.2.2

Arcabit
Trojan.Generic.D2A6FB9
1.0.0.582

AVG
DiCrypt
2017.0.2863

Bitdefender
Trojan.GenericKD.2781113
1.0.20.75

Emsisoft Anti-Malware
Trojan.GenericKD.2781113
8.16.01.15.02

F-Prot
W32/MalwareHiderPatched-based!M
v6.4.7.1.166

F-Secure
Trojan.GenericKD.2781113
11.2016-15-01_6

G Data
Trojan.GenericKD.2781113
16.1.25

MicroWorld eScan
Trojan.GenericKD.2781113
17.0.0.45

nProtect
Trojan.GenericKD.2781113
15.10.08.01

Qihoo 360 Security
HEUR/QVM05.1.Malware.Gen
1.0.0.1015

VIPRE Antivirus
Trojan.Win32.Generic
44470

File size:
116 KB (118,784 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:pIqazsKz1hw3vqmwwSmY8zGvzU0yjCycyBR2ur1Ob7wSwq9:Mzpzs3CmIm5zGjy2xyBJIwJq9

Entry address:
0x17A4C

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, B8, E4, 79, 41, 00, E8, 9E, C7, FE, FF, 33, C0, 55, 68, E0, 7B, 41, 00, 64, FF, 30, 64, 89, 20, E8, 63, AC, FE, FF, 85, C0, 0F, 85, 04, 01, 00, 00, DB, 2D, EC, 7B, 41, 00, E8, D8, AC, FE, FF, D9, E1, D8, 1D, F8, 7B, 41, 00, DF, E0, 9E, 0F, 84, E8, 00, 00, 00, DB, 2D, FC, 7B, 41, 00, E8, A4, AC, FE, FF, D8, 1D, 08, 7C, 41, 00, DF, E0, 9E, 0F, 84, CE, 00, 00, 00, 8D, 45, EC, 50, B9, 10, 00, 00, 00, BA, 01, 00, 00, 00, B8, 14, 7C, 41, 00, E8, C9...
 
[+]

Entropy:
6.0270

Developed / compiled with:
Microsoft Visual C++

Code size:
91.5 KB (93,696 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security