File verdict·Decided by the MT AI Engine
Our call

Malicious

Strong tier-1 consensus on MalwareX family plus process injection and direct-IP C2 behaviour.

malwarex
Trust score12Critical
Setup.exe
4.3 MB
24100b43cdef8a018bfc26a36c1f
Antivirus engines
28 of 75 flagged
Code signing
Unsigned
Age
First seen 2mo ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

82%Confidence
High
Reasoning

The tier-1 family consensus on malwarex is decisive: four high-trust engines converged on the same family while eleven tier-1 engines overall reported malicious. Offensive MITRE techniques T1055 and T1543.003 plus the high-severity ProcessInjection heuristic indicate active evasion and persistence attempts. Direct-IP C2 to four addresses without DNS usage is a classic malware pattern. The file is unsigned, has zero reputation, and no similar-hash RAG history to suggest prior clean distribution.

Key signals · 4

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1FamilyConsensus.strong=true (family=malwarex, 4 agreeing tier-1 engines)

  2. behaviour.offensiveTechniques=[T1055, T1543.003] and triggeredHeuristics MalwareTips.Synth.ProcessInjection (high)

  3. signing.signed=false with contactedIps showing direct-IP C2 (45.32.1.23, 23.11.33.159)

  4. engines.topDetections includes Avast Win64:MalwareX-gen, Avira ADWARE/W64.MalwareX, Kaspersky HEUR:AdWare.Win32.PCAppStore.gen

Points in its favour
  • no malicious sandbox verdict returned
  • no known-malicious contacted hosts in cache
  • no dropped malicious children
Points against
  • tier1FamilyConsensus.strong=true on malwarex
  • offensive MITRE T1055 and T1543.003 observed
  • direct-IP C2 with zero DNS usage
  • unsigned with 0 reputation and 31-day age
Recommended action

Treat as malicious PUA; block execution and remove any installed PCAppStore/VeryFast components.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Hides inside another running program to evade antivirus.

  • High concern: Records what you type — keylogger behaviour.

  • High concern: Talks to a remote server to take commands or send out your data.

  • High concern: Installs itself as a Windows service to stay running.

  • High concern: Sets itself to run automatically every time you start your PC.

  • High concern: Tries to disable or bypass your security software.

  • Moderate concern: Obfuscates or packs its code to avoid detection.

Translated from the file's technical behaviour during analysis. It never ran on your device.

Threat context

How bundlers & adware work

This is a bundler — a real-looking installer that hides extra software inside. When you run it, it quietly installs things you never asked for: ad injectors, browser toolbars, fake 'PC cleaner' apps, or even more bundlers. The people behind it get paid for every unwanted app they sneak on.

Bottom line:It's not usually built to destroy files, but it slows your PC, floods it with ads, and can be a real pain to fully remove.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.

  3. From a different, clean device, change the passwords on your important accounts (email and banking first) and turn on two-factor authentication.

  4. In future, only download software from the official website or an official app store.

Threat family attribution

pcappstore corroborated by 2 sources

  • VT (75 engines)
    pcappstore
  • MT AI Engine
    malwarex
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
28

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1027· Obfuscated codeT1027.002· Obfuscated codeT1033· Reads user infoT1047T1055· Process injectionT1056.001· KeyloggingT1057· Lists programsT1059· Runs commandsT1071· Remote server (C2)T1082· System reconT1083· Scans your filesT1112T1129· Loads modulesT1489· Stops servicesT1497· Sandbox evasionT1497.002· Sandbox evasionT1518· Checks your AVT1518.001· Checks your AVT1543.003· Service installT1547.009· Auto-startT1562· Disables securityT1564.003· Hides artifactsT1569.002+4 more
Spawned processes
8
$(unnamed)
"C:\Users\<USER>\Desktop\Setup.exe"
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
C:\Windows\System32\svchost.exe -k NetworkService -p
$(unnamed)
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
$(unnamed)
C:\Windows\system32\lsass.exe
$(unnamed)
C:\Windows\system32\svchost.exe -k LocalService -s W32Time
$(unnamed)
"C:\Users\user\Desktop\Setup.exe"
Network activity
12
IP addresses4
  • 45.32.1.23
  • 23.11.33.159
  • 8.8.8.8
  • 209.222.21.115
URLs8
  • https://pcapp.store:443/inst_cpg.php?guid=60E3CDBD-D39E-11EF-9E8E-B8CA3A66C878&version=fa.2046&src=g_inst&uc=16le&i_type=10&_fcid=1780766902097379
  • https://pcapp.store:443/pixel.gif?guid=60E3CDBD-D39E-11EF-9E8E-B8CA3A66C878&version=fa.2046&evt_src=fa_g_installer_cpp&evt_action=show_page&p=wel&_fcid=1780766902097379&i_type=10
  • http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEAJmJ%2B0%2F3085KKQ3%2BQaGR1I%3D
  • https://pcapp.store/inst_cpg.php?guid=8CE01CC0-882F-4658-9A78-B9AA408651DF&version=fa.2046&src=g_inst&uc=16le&i_type=10&_fcid=1780766902097379
  • https://pcapp.store/pixel.gif?guid=8CE01CC0-882F-4658-9A78-B9AA408651DF&version=fa.2046&evt_src=fa_g_installer_cpp&evt_action=show_page&p=wel&_fcid=1780766902097379&i_type=10
  • https://pcapp.store/pixel.gif?guid=8CE01CC0-882F-4658-9A78-B9AA408651DF&version=fa.2046&evt_src=fa_g_installer_cpp&evt_action=emulated_click&p=wel&_fcid=1780766902097379&i_type=10
+2 more
Filesystem & mutexes
5
Files written3
  • C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
  • C:\Users\user\AppData\Local\Microsoft\Windows\INetCache
  • C:\Users\user\AppData\Local\Microsoft\Windows\INetCookies
Mutexes created2
  • PCAppStoreMutex
  • \Sessions\1\BaseNamedObjects\PCAppStoreMutex
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

3 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\System32\svchost.exe -k NetworkService -p
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
  • DirectIpC2medium

    Sample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    45.32.1.23 · 23.11.33.159 · 8.8.8.8
Antivirus engine breakdown

28 detections across 75 engines

28 malicious0 suspicious47 clean
Tier-117 engines
11flag
Top commercial AVs (low FP rate)
Tier-241 engines
12flag
Mainstream engines with mixed FP rates
Low-trust17 engines
5flag
Heuristic / generic-AI engines (high FP rate)
AhnLab-V3
malicious
PUP/Win.PCAppStore.R777103
ALYac
malicious
Trojan.Generic.40015369
Arcabit
malicious
Trojan.Generic.D26295EE [many]
Avast
malicious
Win64:MalwareX-gen [Misc]
AVG
malicious
Win64:MalwareX-gen [Misc]
Avira
malicious
ADWARE/W64.MalwareX
BitDefender
malicious
Trojan.Generic.40015342
CTX
malicious
exe.trojan.generic
Cynet
malicious
Malicious (score: 99)
DrWeb
malicious
Program.Unwanted.5544
Elastic
malicious
malicious (high confidence)
Emsisoft
malicious
Trojan.Generic.40015342 (B)
ESET-NOD32
malicious
Win32/Adware.VeryFast.Q application
F-Secure
malicious
Adware.ADWARE/W64.MalwareX
Fortinet
malicious
Riskware/VeryFast
GData
malicious
Win32.Trojan-Ransom.PCAppStoreLocker.A
Google
malicious
Detected
Gridinsoft
malicious
PUP.Win64.PCAppStore.oa!s1
K7AntiVirus
malicious
Unwanted-Program ( 005ce0731 )
K7GW
malicious
Unwanted-Program ( 005ce0731 )
Kaspersky
malicious
not-a-virus:HEUR:AdWare.Win32.PCAppStore.gen
Malwarebytes
malicious
PUP.Optional.VeryFast
MicroWorld-eScan
malicious
Trojan.Generic.40015342
Rising
malicious
PUA.FastApp@XH.1FBD (CERT:yqBmFCPIMzqYeYrfIC+fSQ)
Varist
malicious
W64/ABApplication.KSPD-4216
VBA32
malicious
Adware.PCAppStore
VIPRE
malicious
Trojan.Generic.40015342
Webroot
malicious
Win.Deceptor.Pcappstore
Hash 24100b43cdef… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.68Unpacked
Section entropy7 sections
.text
6.46
.rdata
5.36
.data
4.51
.pdata
5.96
.fptable
0.00
.rsrc
7.99
.reloc
5.38
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
1
Very few people have ever uploaded this — rare.
Total submissions
1
Includes repeat uploads by the same source.
First seen
2mo ago
Jun 6, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/6/2026, 1:44:22 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/6/2026, 1:44:22 PM
Scanned here
7/7/2026, 11:54:04 PM
File name
Setup.exe
Size
4.35 MB
MIME type
application/x-msdownload
Detected type
Win32 EXE
SHA-256
24100b43cdef8a018bad380d223a2825b8eb33b3e7bcacaae316eefc26a36c1f
MD5
89131076b31dfff1ac51c6def46f5328
SHA-1
e195b6f140d0fcdf3224e8bf5fe57d4dce3ebb82
PE imphash
6baf91e587892c296d304b3daf25a3cd
First seen (VT)
6/6/2026, 1:44:22 PM
Last analysis (VT)
6/6/2026, 1:44:22 PM
First scan (MalwareTips)
6/6/2026, 1:45:03 PM
Last scan (MalwareTips)
7/7/2026, 11:54:04 PM
Behavior tags
peexeoverlay64bitschecks-user-inputcalls-wmichecks-disk-spacechecks-bios
Frequently asked

Safety FAQ

Common questions about Setup.exe, answered from the scan data above.

  • Yes — Setup.exe is malicious, so do not run it, and delete it. 28 of 75 antivirus engines flag it (family: malwarex). It behaves as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. If you've already run it, see the removal and recovery steps below.
  • Setup.exe is a Windows executable program (application/x-msdownload), about 4.3 MB. Our analysis identifies it as malicious (family: malwarex) — adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
  • 28 of 75 antivirus engines flagged Setup.exe, 28 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove Setup.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Setup.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • Setup.exe is classified as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Engines attribute it to the malwarex family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
  • The SHA-256 hash of Setup.exe is 24100b43cdef8a018bad380d223a2825b8eb33b3e7bcacaae316eefc26a36c1f, and its MD5 is 89131076b31dfff1ac51c6def46f5328. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on June 6, 2026. Because a file's hash never changes, the identity of Setup.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.