ssetup.exe

0.9.8.0

Secure Download

The application ssetup.exe, “SearchAssist Setup ” by Secure Download has been detected as adware by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from dgekaihxawqz1.cloudfront.net.
Publisher:
SearchAssist   (signed by Secure Download)

Product:
0.9.8.0

Description:
SearchAssist Setup

Version:
0.9.8.0

MD5:
ba8463870354efdf929f21ac29eb9f82

SHA-1:
0b2dd250546991cda9edff61e8663c12441eca60

SHA-256:
4c2f3e06db08d41295cd095ca47addf0895f22957ca09015effb775c44a16469

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
5/4/2024 7:42:34 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2687
9.0.1.05190

Reason Heuristics
PUP.Installer.SecureDownload.G
14.9.21.5

File size:
2.5 MB (2,649,328 bytes)

Product version:
0.9.8.0

Copyright:
Copyright 2014, SecureDownload Ltd

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\ssetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/1/2013 1:00:00 AM

Valid to:
4/2/2015 12:59:59 AM

Subject:
CN=Secure Download, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Secure Download, L=Varna, S=Varna, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
33603C68EE7C09737EB44A0122AD5A1D

File PE Metadata
Compilation timestamp:
10/13/2013 9:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:IngiUH02nTRbenfptrlBl0n+2OcsMuH4Kh6QRT2w5l7aseH:MBk9benxPBCnecs/H4gIuusY

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9807

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file ssetup.exe has been seen being distributed by the following URL.

Remove ssetup.exe - Powered by Reason Core Security