fuzezipsetup-r145-w-bi.exe

FuzeZip

Koyote-Lab Inc.

The application fuzezipsetup-r145-w-bi.exe by Koyote-Lab has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.fuzezip.com.
Publisher:
Koyote-Lab Inc.  (signed and verified)

Product:
FuzeZip

Description:
FuzeZip Install

Version:
1.0.0.135157

MD5:
d473ab93948ff613fb62c7f4c4c8c1a9

SHA-1:
ab535b4c6f7e2f171fd3a0917493ad7e2ae79de9

SHA-256:
ef6e4a731e474398de9a59d217343bf280c4330183e2adf94539ea28f8725c64

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/14/2024 11:51:36 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bandoo (M)
17.2.10.3

File size:
1.5 MB (1,616,152 bytes)

Product version:
1.0.0.135157

Copyright:
Copyright (c) 2014 Koyote Soft

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\fuzezipsetup-r145-w-bi.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/11/2014 5:00:00 PM

Valid to:
2/21/2016 4:59:59 PM

Subject:
CN=Koyote-Lab Inc., OU=DEV, O=Koyote-Lab Inc., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
05787E08EB7454E434F666A81F251A2D

File PE Metadata
Compilation timestamp:
5/30/2013 2:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
7.9006

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file fuzezipsetup-r145-w-bi.exe has been seen being distributed by the following URL.

http://download.cdn.fuzezip.com/cdn/r/.../FuzeZipSetup-r145-w-bi.exe

Remove fuzezipsetup-r145-w-bi.exe - Powered by Reason Core Security