winsetupfromusb-1-1.exe

7-Zip

Igor Pavlov

The program is a setup application that uses the 7z Setup installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7z SFX

Version:
9.30 alpha

MD5:
6cfdab6b633764c4c9fac99acf132927

SHA-1:
18d5032d0fa676708118124e3a17b2feb92e9b2a

SHA-256:
e2309d2758fe43d182e202b3a00d4e2af4c39fc46349b2814c2bc5184027c589

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 7:14:08 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14323

Trend Micro House Call
TROJ_GEN.F47V1209
7.2.84

File size:
21.6 MB (22,619,852 bytes)

Product version:
9.30 alpha

Copyright:
Copyright (c) 1999-2012 Igor Pavlov

Original file name:
7z.sfx.exe

File type:
Executable application (Win32 EXE)

Installer:
7z Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\winsetupfromusb-1-1.exe

File PE Metadata
Compilation timestamp:
10/26/2012 1:03:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:qASorLaXJNOqIfFdis4uoXMnc2ald1Oo18Vstr07RD0IX2Kr+i4r9Cm4:7/YTOq2Guuwc7D1JYs07RD0vQ+iOCX

Entry address:
0x1DC22

Entry point:
55, 8B, EC, 6A, FF, 68, 90, 1E, 42, 00, 68, 1C, DC, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 34, 11, 42, 00, 59, 83, 0D, 74, BE, 42, 00, FF, 83, 0D, 78, BE, 42, 00, FF, FF, 15, 30, 11, 42, 00, 8B, 0D, 5C, 9E, 42, 00, 89, 08, FF, 15, 2C, 11, 42, 00, 8B, 0D, 58, 9E, 42, 00, 89, 08, A1, 28, 11, 42, 00, 8B, 00, A3, 70, BE, 42, 00, E8, 1F, 01, 00, 00, 39, 1D, 10, 7A, 42, 00, 75, 0C, 68, 79, D3, 40, 00, FF, 15, 24, 11...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
126 KB (129,024 bytes)

The file winsetupfromusb-1-1.exe has been seen being distributed by the following 23 URLs.

http://gsf-cf.softonic.com/18d/503/.../file?SD_used=0&channel=WEB&fdh=no&id_file=85492&instance=softonic_en&type=PROGRAM&Expires=1428901232&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Gs8W7iDvSQ0aIu3x3NpyOMc6-nZzA6LJR1GNd6NVy5tMGCmTr7L6FHbx6chJfdw9OgAgB-ZOK1PLceGj5GabTGNM446rpF3SFqokwruQFqWZqP1DsO9iH6V0-pT5G3oI~9PDv5xgdYK7jfXN4mIJBq1GnT2ql836cSp6TBfvvmg_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com/18d/503/.../file?SD_used=0&channel=WEB&fdh=no&id_file=85492&instance=softonic_fr&type=PROGRAM&Expires=1418263329&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=KeCoarkOAsp4tyWsNiHUGXbdPxb7WMEbwZDlseyBUHLrK-NbtauSbe4tVA5Ph6HshCg7~LZVME1WrRQTBpxemRw25kTLOsRFaDpcAJQXlyRs01gROcq1mFOY3W9hkuyd5FYlcaapQ4StS9xcjq8VWyOLDRfRwTJhTkpZsgN2kDw_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com//18d/503/.../file?id_file=85492&channel=WEB&instance=softonic_es&type=PROGRAM&fdh=no&SD_used=0&Expires=1403005391&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=EDNY~NMM4fCH-mOtiPaQF8MjUImtxW6X4BAtmaa0PVoIvdfRbNWA17LTuXU4H7UQayvTLtS4EZs5KzAf88UhGlGsrFlA3UGU~V7Hu8mw9JsKeJu7u3Kxvy2H6o3ZiMZBiPAAUFYB2ldTbmOM6xTbhNpSEROjXZ99PyzLaK6pN2Q_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com/18d/503/.../file?SD_used=0&channel=WEB&fdh=no&id_file=85492&instance=softonic_es&type=PROGRAM&Expires=1428472589&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=SoSICfZREsR~JTMY~pHaATn27TmOyFCunQFfxFCp4YyqWI8ZvE2B~LooRtoaL5bhPxfD3CfXOb5gsp665jQFRa01hsFOvfVX-zzuNp1zJ4dKzMW5Exw-qKggxwff00EYOj8bRDjDtuNWDc1pJxSQo3L0L6kX2PUtnRUcLlzqYwA_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com/18d/503/.../file?SD_used=0&channel=WEB&fdh=no&id_file=85492&instance=softonic_en&type=PROGRAM&Expires=1426911980&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=OCZt0t94Lypc2W8L7t9y~rDHPiDaFRksl30zkOhZL~7528pifCrR0ha8jbPzdh8LA~g0s71RNrCeLHQ-PybGEhDWeZprsjuOE4DQzjJaN4WtFKMtdaWaRp1AhcGKIqWPbf~SAixE9rhEi2fxvSKG~wcgtnNgFrz0KvVmgs-Xves_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com//18d/503/.../file?id_file=85492&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=no&SD_used=0&Expires=1405487127&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=WKT7WRwvlnaHZ7pOtu5ZzLUkynKTyKuSA67afgazsm3lW-BzGVyeq29A0fFJFwBoNMjdXVFA3~dN6VMptrsKuney3Asrjh-GCIjc7nRB3cAojxxCWrk1UkN-pj93KCRWI~KWX6Ap6eYIpWBZFB92ZliyoJr1Se31iRnqIFmQ5W0_&filename=WinSetupFromUSB-1-1.exe;

http://gsf-cf.softonic.com//18d/503/.../file?id_file=85492&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=no&SD_used=0&Expires=1390726165&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=PLMNCVPFcHCCjDVwJEv5DP9POfefva-rcnEs4lWpd4~TfjE4uumy5Zqi4vO231m282rtINuQvmMvVq~6Ds79iK335hSWNkA~swjRdPhFEXWrI9ePIcRAGxkTbUTV5WqhKKjZCMPa-4HaWWqw5SNq7yKue4A8fB6AIdY~isRnrpg_&filename=WinSetupFromUSB-1-1.exe;

Scan winsetupfromusb-1-1.exe - Powered by Reason Core Security