hdsetup.exe

Gomeha

OOO ELEKTRO-KOD

The application hdsetup.exe, “Gomeha Setup ” by OOO ELEKTRO-KOD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.deliveryconecptranch.com.
Publisher:
Cobopuh   (signed by OOO ELEKTRO-KOD)

Product:
Gomeha

Description:
Gomeha Setup

Version:
2.5.3.7

MD5:
df0776ae6e879a71b3409467bbd7b8cf

SHA-1:
7a173ac6eb790da20740e9b85af07b69cb4908e3

SHA-256:
5d24e3ad31a63df983bf95528bf43ee6ed3f7b133dfb3f305669c92a996f03f1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/31/2024 11:33:01 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.16.0

File size:
1.2 MB (1,239,416 bytes)

Product version:
5.1

Copyright:
Lite

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hdsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/15/2016 8:00:00 AM

Valid to:
4/16/2017 7:59:59 AM

Subject:
CN=OOO ELEKTRO-KOD, O=OOO ELEKTRO-KOD, STREET="ul. Ibragimova, d. 35 str. 2 Pom I Komn 14", L=Moscow, S=Moscow, PostalCode=109428, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2EC7061CBC4E49BEE7F530967BE4F7BC

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9846

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file hdsetup.exe has been seen being distributed by the following URL.

http://www.deliveryconecptranch.com/LsjGFYzs9kcRsJwMxJuCKZZ76mB9WkWNC_B8sC3sKCxEPNcgrMy_MZwe3CBE ZQbTFOCxjUdqAnbxJ3bI4TKU90u3ii2sXwb9p_2pp8yVm4nGexuGHMfD 2WyQ4N STPKG0wbcVb9d7skTEaljtrtyWflpDHTx9Ee2OAfIsHX2w2l0h2VaWzUxuh5q8Ox9Rnvux5sAAg2cvB79yF5_9Vr6itfy3u_4f P1A6aqp7Cc3PMifY34Y qj7LXjwdobsDNEhNwU0VmCGf26iYHbRn6e MbnC6WtpNO53S0jKsYEQ1ezGe12cy8sS0zFuyDIJj_y5fAXK3rIqt9z2liqSjmgYnAqrgtRrZfv4zk C_P8AuUABUfPuSxnrRMzXXaz1cabIwr6OtDUDyeOPd271e7CTMST204_yGi2Afi3SPphoB0JZ2ORiH hcpce5BqfMxPVID8mGjAz3UruunO9bsa6GFPDMGD4oS4mLhIvwzL1AwDywpp8XzBUsavda1VxauO9pNOZnrC_jWZa5R6mYSsBDJGoOPn8sDQXxr5zIlHcE zF_5bTWcBy7U bIB3oubSmPx6YtLSGAU2nCCiECqMAZPxx_FL OUA9_2ukdNGfuBdCBHoB7InixGnZNnWANtU0byKpIH8ymUB8yv5g6Z0mvc61XLpQ1Sbz8S5vC5mdgjYo4Lg2BIfLMmXN3Yw9C9CX7drfWynzpow_nMnQ7NHJe4zstbwg0ylWyWQ9orPvsy6O2JMe0Sf0SUeP73TnK79pCYjsiEsJByGB9oTCp_WB1FZIT8fzGDJSBXK_KH4XNV6MaYv0UcLr8XslAfPCtQ4R0T2zXK YT_79o TCQcJSSz27X4 wIPQ6s5m4Vmg2OAEo0RAxsZTfsed8TO9pdRpvfiTID29HUU9K42MwHzNp_DU3L8gHH8lfX uAerDGP4v2wsk7Pq0_YLlk9qMIErKmu

Remove hdsetup.exe - Powered by Reason Core Security