tmp000000462f2f08a039524f05

Installer Setup

This is part of the Air Installer, a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file tmp000000462f2f08a039524f05 by Installer Setup has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Installer Setup  (signed and verified)

Version:
1.0.1.0

MD5:
b7a5d41c42879cd1cf4e80e2c4ad51c3

SHA-1:
86ba40a7a83b23a560b2b78368a2624856760566

SHA-256:
d52a1b7089749d09d3f71ac32f3494feec770287acc7185712f8f5247b5e6835

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
6/20/2025 4:48:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Air Software.Installe (M)
16.5.10.3

File size:
512 KB (524,288 bytes)

Product version:
1.0.1.0

Copyright:
Copyright (C) 2015

Original file name:
ChromeSt.exe

Language:
English (United States)

Common path:
C:\windows\temp\tmp000000462f2f08a039524f05

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/8/2015 5:00:00 PM

Valid to:
9/8/2016 4:59:59 PM

Subject:
CN=Installer Setup, O=Installer Setup, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1021E089A110C6095910FA179448796C

File PE Metadata
Compilation timestamp:
10/8/2015 11:36:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:tUZxfx8oh0HanPs9zjRR3z8HvLTbQSjm3PZhaSysDaVK5CV+/VSLsfkEl1ae:tyj8R9zlR3zkT3Qn/pysKK5QWD1a

Entry address:
0x14382

Entry point:
E8, F7, 78, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C...
 
[+]

Entropy:
6.8291

Code size:
151 KB (154,624 bytes)

Remove tmp000000462f2f08a039524f05 - Powered by Reason Core Security