zipopenersetup.exe

The application zipopenersetup.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore monetization download manager to download additional third party applications that may be unwanted by the user. The file has been seen being downloaded from www.ziputil.net.
MD5:
1cb9b608f393f74b18efc8f8c17936d6

SHA-1:
93d1f51d16f89b4637eb7bd5210fe8aa21d8dc25

SHA-256:
44a73e217da0731beb091ecbb46bd0ada2a6f35cff3b440eb15ad4d4ab5432f5

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 4:24:13 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Packed.24524
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Generic.15539276
10.0.0.5366

ESET NOD32
Win32/Kryptik.BWJC trojan
7.0.302.0

Microsoft Security Essentials
Threat.Undefined
1.213.3386.0

Norman
Trojan.Generic.15539276
11.01.2016 17:30:26

Sophos
PUA 'Install Core Click run software'
5.23

VIPRE Antivirus
Threat.4786018
46446

File size:
665.5 KB (681,424 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\zipopenersetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:m0DUwCPHmCEqQ26YcVT1Afy9PW1eyef5SiJ7futQkf/BfkV:m0jC+CEf24iK97yeBSCfuaSlk

Entry address:
0x9B24

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, A2, 95, FF, FF, E8, A9, A7, FF, FF, E8, D4, C9, FF, FF, E8, 1B, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, DB, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, A4, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 04, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 53, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.7959

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file zipopenersetup.exe has been seen being distributed by the following URL.

Remove zipopenersetup.exe - Powered by Reason Core Security