adobe-reader-xi-11-0-04_softpom.exe

The application adobe-reader-xi-11-0-04_softpom.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from fr.softpom.com.
MD5:
6ec86137bbbc962c44f738105a8bae77

SHA-1:
f6754f9f0aa8363221de27203dd093bacc0e4f88

SHA-256:
5b5d8de47646621ae24a7df2e87817ccba2cab982975ec8393d404c04b55e4bc

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 1:29:24 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.127.54

Dr.Web
Trojan.Packed.24524
9.0.1.042

ESET NOD32
Win32/InstallCore.FJ (variant)
8.9338

Malwarebytes
v2014.02.11.07

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14209

SUPERAntiSpyware
10789

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
InstallCore
25802

File size:
692.6 KB (709,232 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adobe-reader-xi-11-0-04_softpom.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ayMJfsGhR+3aZAAY9lmUwStF9n5ZcJRbwqjPeswRRGGo6w/GXbfyWmBkRAbQF8:ayMJfsyMaZZ2nlF6RbjerDu/SaIb

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Code size:
36 KB (36,864 bytes)

The file adobe-reader-xi-11-0-04_softpom.exe has been seen being distributed by the following URL.

Remove adobe-reader-xi-11-0-04_softpom.exe - Powered by Reason Core Security