Setup.exe

Sex Messenger

Rentabiliweb Belgique

The file Setup.exe by Rentabiliweb Belgique has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. While running, it connects to the Internet address vip1.2town.net on port 80 using the HTTP protocol.
Publisher:
Rentabiliweb  (signed by Rentabiliweb Belgique)

Product:
Sex Messenger

Version:
1.0.0.7

MD5:
70f42008afe4e904375ca49d09583964

SHA-1:
dbe29fa3a11d33331a2a294fc99196aa9fbf6b4f

SHA-256:
ca8a41d9b731c8d934175ef9c89fcd779dbab7ba7ae6f9237e3e87dacbe7290e

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:44:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RentabiliwebBelgique.Installer (M)
15.10.11.14

File size:
140.4 KB (143,760 bytes)

Copyright:
Rentabiliweb

Trademarks:
Sex Messenger is a trademark of Rentabiliweb company

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/28/2014 5:00:00 PM

Valid to:
11/27/2016 3:59:59 PM

Subject:
CN=Rentabiliweb Belgique, O=Rentabiliweb Belgique, L=Bruxelles, S=Saint-Gilles, C=BE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
51836B793C9006E894EEF076C21FFF8A

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:PQIURTXJAchSVLHGzaLXzLmEWoWAIi5o8OI9zq1644Z:PsachmLmzaL38AIsrOAe1G

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
6.8118

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to vip1.2town.net  (91.226.182.241:80)

Remove Setup.exe - Powered by Reason Core Security