setup_magic_ct.exe

3199_pjr_luckysearches

Fuyuan Zhou

The application setup_magic_ct.exe by Fuyuan Zhou has been detected as adware by 13 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from d2drfrdurj6mvo.cloudfront.net.
Publisher:
ogu  (signed by Fuyuan Zhou)

Product:
3199_pjr_luckysearches

Description:
ogu

Version:
6,3,7601,2017

MD5:
b4cd8cd501d7a96381e4c0a1b4f04cd8

SHA-1:
c1261ac1ce6097a0b157b85e5507cad4092157ff

SHA-256:
10f1982e4b54f374234ee614798f47cf6bc02e993ac6117504d226102e53a1e5

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
5/12/2024 2:09:20 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Evo-gen [Susp]
2014.9-150623

AVG
Potentially harmful program Downloader
2016.0.3069

Baidu Antivirus
PUA.Win32.ELEX
4.0.3.15317

Dr.Web
Adware.Mutabaha.228, Adware.Mutabaha.190
9.0.1.0174

ESET NOD32
Win32/ELEX.CE potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.6.23.15

K7 AntiVirus
Trojan
13.201.15304

Malwarebytes
PUP.Optional.IStartSurf.A
v2015.03.17.07

McAfee
Program.Artemis!349860BEB904
5600.6725

Reason Heuristics
PUP.Installer.FuyuanZhou
15.3.17.18

Sophos
PUA 'Elex' (of type Adware)
5.13

Trend Micro House Call
Suspicious_GEN.F47V0318
7.2.174

VIPRE Antivirus
Threat.4726263
38050

File size:
179.1 KB (183,392 bytes)

Product version:
6,3,7601,2017

Copyright:
ocjs

Original file name:
ogu

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup_magic_ct.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
1/14/2015 4:00:00 PM

Valid to:
1/20/2016 4:00:00 AM

Subject:
CN=Fuyuan Zhou, O=Fuyuan Zhou, S=Jilin, L=Jilin, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F23159AB625CE992A314C35F55B4F8E

File PE Metadata
Compilation timestamp:
3/16/2015 1:04:13 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:Qxy0k7iy0KLwD2DvG6Bo0p3LsZ/pABZ+phU9Xx6W8Q5ZK:Qxk7iy0fKzGCvhIpABZWmpt5ZK

Entry address:
0x106D6

Entry point:
E8, C7, 62, 00, 00, E9, 7F, FE, FF, FF, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 74, 76, 42, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, C8, 50, 42, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, 74, 76, 42, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00, 00, 00...
 
[+]

Code size:
104 KB (106,496 bytes)

The file setup_magic_ct.exe has been seen being distributed by the following URL.

http://d2drfrdurj6mvo.cloudfront.net/.../pjr_luckysearches.exe

Remove setup_magic_ct.exe - Powered by Reason Core Security