setup.exe

Dream Hands Co.,Ltd

The application setup.exe by Dream Hands Co.,Ltd has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Dream Hands Co.,Ltd  (signed and verified)

MD5:
de37520f0dc4ca305154dafb8eb79af0

SHA-1:
ee60e10b8a1fdc921c2234f75a75de68a5cc5200

SHA-256:
2f6d62c88796fc353843786bd4cc3133de554e6ec4536b0e3292edbecc78ccc8

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
5/7/2024 12:44:25 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.02.10

Avira AntiVirus
HEUR/Malware
7.11.209.28

Comodo Security
Worm.Win32.Bundpil.D
21019

Dr.Web
BackDoor.Infector.133
9.0.1.0251

ESET NOD32
Win32/Packed.Themida suspicious (variant)
9.11149

McAfee
Artemis!DE37520F0DC4
5600.6649

NANO AntiVirus
Riskware.Win32.Agent.dagpce
0.30.0.65070

Norman
Suspicious_Gen4.GRUAE
11.20150908

Qihoo 360 Security
HEUR/Malware.QVM19.Gen
1.0.0.1015

Rising Antivirus
PE:Worm.Gamarue!6.4C
23.00.65.15906

Trend Micro House Call
Suspicious_GEN.F47V0201
7.2.251

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
18.7 MB (19,636,352 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/12/2014 9:00:00 AM

Valid to:
3/13/2015 8:59:59 AM

Subject:
CN="Dream Hands Co.,Ltd", OU=IT Team, O="Dream Hands Co.,Ltd", L=Haewoondae-gu, S=Busan, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
556CF438F8C692CA0E7A478AFEC20F2D

File PE Metadata
Compilation timestamp:
12/6/2009 7:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:OUwwgE1XKMtK8T3CaIFRvqpvMmYeROCf4+rFjLdtcYGErDgWtnd:OUww9JrtfTZIFRbSOCprFjXdrDtnd

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9984

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup.exe - Powered by Reason Core Security