setup.exe

VOLARO Ltd.

The application setup.exe by VOLARO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.freearabsofts.com.
Publisher:
VOLARO Ltd.  (signed and verified)

MD5:
7daf08cebf81b2d6a64c56f4bc2bfc4b

SHA-1:
c1d0fa95a8641267e399c9cd68067f5cb8c390e3

SHA-256:
3a610c61f8a22eb6c672d0a69c0bfcf221b69fd6caaf13305a40b3dcf804738b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 12:30:31 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.10.18

File size:
1.3 MB (1,355,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/15/2013 2:00:00 AM

Valid to:
2/28/2014 1:59:59 AM

Subject:
CN=VOLARO Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=VOLARO Ltd., L=Sofia, S=Bulgaria, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
45902E82A000D2497C38FE709EF124BC

File PE Metadata
Compilation timestamp:
7/17/2013 7:56:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x3397

Entry point:
E8, 57, 47, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B...
 
[+]

Entropy:
7.9459  (probably packed)

Code size:
51.5 KB (52,736 bytes)

The file setup.exe has been seen being distributed by the following URL.

http://www.freearabsofts.com/.../download.php?wti=114&src=114&sta=00011629b34dacf2943f1b31a696b38c252ce

Remove setup.exe - Powered by Reason Core Security