setup.exe

The application setup.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. The file has been seen being downloaded from d24p1vpeyzkq4h.cloudfront.net.
MD5:
37b6343a649778993747a8be14b81cb3

SHA-1:
e8b679f51d4cf245e2c57de77bafdd26cc093eb4

SHA-256:
b0554082dcbafb230ccb4f2157c58b29f8a88c789bf537f01e9bd7068ffdd805

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 9:41:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
DR/Delphi.Gen8
8.3.2.2

AVG
DiCrypt
2017.0.2853

Baidu Antivirus
PUA.Win32.DealPly
4.0.3.16125

ESET NOD32
Win32/DealPly.BU potentially unwanted (variant)
10.12433

Fortinet FortiGate
Riskware/DealPly
1/25/2016

IKARUS anti.virus
PUA.DealPly
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.211.17582

McAfee
RDN/Generic.dx
5600.6509

NANO AntiVirus
Trojan.Win32.Delphi.dwxgyn
0.30.26.3947

Rising Antivirus
PE:Malware.RDM.36!5.2A[F1]
23.00.65.16123

Sophos
Mal/Generic-S
4.98

VIPRE Antivirus
Trojan.Win32.Generic
44670

File size:
527.5 KB (540,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:a12n0bH3+MW9gQ3K5EJK9G/Hvl/93Rl/93aVZDSJWQUWl/Dl/I:a12naH3+M/Q3kOHb3R3u/QUP

Entry address:
0x7F5E4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 7C, F5, 47, 00, E8, EC, 4D, F8, FF, E8, F3, 30, F8, FF, 3D, C1, 00, 00, 00, 0F, 85, D8, 00, 00, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 49, 98, 91, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 70, B5, 7C, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 1E, 5F, 0D, 00, A7, 49, 7E, 00, 22, B5, 7C, 00, 61, 47, 00, 00, 79, 78, 0C, 00, 00, 2E, 79, 05, 49, 98, 91, 00, 57, 66, 0C, 00, 67, B3, 7C, 00, 49, 98, 91, 00, A7, 49, 7E, 00...
 
[+]

Entropy:
4.6334

Developed / compiled with:
Microsoft Visual C++

Code size:
506 KB (518,144 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security