setup_osu.exe

OSU

INSTALLER TECHNOLOGY CO.

This installer routine uses the Babylon network to include bundled offers of potentially unwanted programs (mostly search adware) such as toolbars and browser extensions. The application setup_osu.exe, “Open Software Updater” by INSTALLER TECHNOLOGY CO has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from installopensoftware.com.
Publisher:
Installer Technology Co  (signed by INSTALLER TECHNOLOGY CO.)

Product:
OSU

Description:
Open Software Updater

Version:
3.0.0.0

MD5:
606429f32839d87f2006d5e2dedeb9cd

SHA-1:
4669a7ff6cb4c8d94ee3fca37a87c3e6cdd2c4fe

SHA-256:
bef019e84249222c151738b2aae1cb3f1d8a015f7ac273cf258105ecbc94f5c7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 5:35:01 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.INSTALLERTECHNOLOGYCO.J
14.8.8.0

File size:
189.1 KB (193,656 bytes)

Copyright:
Copyright Installer Technology Co. 2014

File type:
Executable application (Win64 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup_osu.exe

Digital Signature
Subject:
CN=INSTALLER TECHNOLOGY CO., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=INSTALLER TECHNOLOGY CO., L=Miami Beach, S=Florida, C=US

Serial number:
4556C69814691A6077AE1628567ACB9F

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
3072:4oPyys5jXJ347g0UNmnB2cbliyhc9nHHmbh6f+xMBHVz56YjHxsz0:4zfQ2NmnB9JiyknHHG7xaGGCz

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.6195

Packer / compiler:
Nullsoft install system v2.x

The file setup_osu.exe has been seen being distributed by the following URL.

Remove setup_osu.exe - Powered by Reason Core Security