hdsetup.exe

Fokoh

OOO ELEKTRO-KOD

The application hdsetup.exe, “Fokoh Setup ” by OOO ELEKTRO-KOD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.laboratoryclearworld.com.
Publisher:
OOO ELEKTRO-KOD  (signed and verified)

Product:
Fokoh

Description:
Fokoh Setup

MD5:
3059977f80c4549d0c2da70685ab3e3a

SHA-1:
b31c5ef3ce48d55a2b4ff0635b0019bb242afa2c

SHA-256:
6beb01276e7f4c58f44e78e88069de4c62a56c5243dafa3794ba4505235a37bb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/20/2024 8:47:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
17.3.16.11

File size:
1.2 MB (1,277,888 bytes)

Product version:
1.5

Copyright:
Web

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hdsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/14/2016 5:00:00 PM

Valid to:
4/15/2017 4:59:59 PM

Subject:
CN=OOO ELEKTRO-KOD, O=OOO ELEKTRO-KOD, STREET="ul. Ibragimova, d. 35 str. 2 Pom I Komn 14", L=Moscow, S=Moscow, PostalCode=109428, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2EC7061CBC4E49BEE7F530967BE4F7BC

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9852

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file hdsetup.exe has been seen being distributed by the following URL.

http://www.laboratoryclearworld.com/HfnpsMQSQlaBdyDnS28rP1IIHEQWSPvFxYVE6g25mJzeCHw9qni1hO2UdI61aYSiz1wY4mvrIX9nUqADwN99DVZLhR9ltXSOk6tOxlsGZqrJNYgN9odOGarlpnA0cgqNC6TGnWm3HQg2oP VHCcbyVK6dOBPnI8Z69fZOnmlMX4wjBhjNd1JQkMaX5RzrYlyxBvkV ay7Pv0XNm2AAINtbvDZv5ylP1w1kXYkbXBUy8 4ez9DxX3sNsVCHqWbX1760 qwoxX9ATXo5 SdWC4mbjBikL2y2YxZ86qWZVg9nyndibFllGNB2 fF lWB6z6FQcLC9B_QqsSbg Z96hcY5qxDfVByLKiO nAELHq PT7Iqx3eQxpQAhPn3jrwu49lKp4O7NOCoSnHYlNvu_BSvL6MOq1wlXSVlb9MFv5aspMvAvDqmrvNfnp5M6PVzFXkx1nTnmW8_qXkmNTwaoCuaz60ecyX45rEmv1Yp_s2f93C52qE4guVijkbTfr4zZ1sw7y20tdyO_Elctmi8cpY3e0PV13 yz7Kzyvat6QSZAqCovvpr_yOtnggqB4pl8r6Dm1w736VuGywrsY6Jgq0NT9HWSX7BEEo310k0hIezSK6zvriDYmEAz3ED5xpBdTBRuVkHinQqOqun6NJ7hhy4GdnoBiCmlW9O8MmhchN0QBcQ9yK_rYBPtVJdvdXIJlcXCVFGuMsApUjHDi_nItedTiXpw_709E a3tBVuxEDsugD8uRlnDUbl0O3jndGjyJOekAcMye0ZSEfEcLTh6nZtIJxU4CYPJtQM4inwCPa0VQFkmLForHUeBEagP18Csp_kiAyNO8_seUVGFZEHeOHDSJ9LAOH TNXkp3f4gFGd wNNuMJCJZUlbr_SjGltqvwk 8lhOLvmk3f9xrAM0mY6hy6ZO8yo2MYH3TUQc2aukkEODQ3lvwCD5OOdLQpk_kJmb

Remove hdsetup.exe - Powered by Reason Core Security