angry birds provided through adscend media network cpa.exe

Interactive Install

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application angry birds provided through adscend media network cpa.exe by LiveSoftAction has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer. The file has been seen being downloaded from stapi.maxrevinstaller.com.
Publisher:
Live Soft Action S.R.L.  (signed by LiveSoftAction)

Product:
Interactive Install

Version:
1.0.11.0

MD5:
09e2f8849858ea30b9bbdb54eb7b4301

SHA-1:
32f3fdf215e12f2530a206b4a5249a6b0b564671

SHA-256:
b8dbdd3e0bf05c2328bb7c0908ae4b4e9119a7efc14dbc7cbf1e963d52492e5e

Scanner detections:
22 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 10:10:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.670831
826

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Adware-gen [Adw]
141025-0

AVG
Adware BundleApp_r.Q
2015.0.3304

Bitdefender
Application.Generic.670831
1.0.20.1520

Comodo Security
Application.Win32.GetNow.NRTI
19086

Dr.Web
Adware.Downware.4801
9.0.1.0304

ESET NOD32
Win32/GetNow.B potentially unwanted application
7.0.302.0

F-Prot
W32/A-a4017d21
v6.4.7.1.166

F-Secure
Application.Generic.670831
11.2014-31-10_6

G Data
Win32.Application.Getnow
14.10.24

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13662

Malwarebytes
PUP.Optional.GetNow
v2014.10.31.09

McAfee
LiveSoftAction
5600.6960

MicroWorld eScan
Application.Generic.670831
15.0.0.912

NANO AntiVirus
Riskware.Win32.Downware.dcskya
0.28.2.60990

Reason Heuristics
PUP.Installer.LiveSoftAction.w
14.10.31.21

Sophos
Live Soft Action
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10265

VIPRE Antivirus
Threat.4794174
31208

File size:
688.8 KB (705,288 bytes)

Product version:
1.0.11.0

Copyright:
(c) Live Soft Action S.R.L. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\downloads\angry birds provided through adscend media network cpa.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2012 7:00:00 PM

Valid to:
6/5/2014 6:59:59 PM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
4/23/2014 8:17:08 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:tU4g4P3bgpL8PmgtzKXJ5niDqIDJRqQoEj1yGqtR571gWL1RAxSV95ePZ50GdTyq:QUqUZB+5i2ItRqUj13qtR571gQRLV457

Entry address:
0x197880

Entry point:
60, BE, 00, 40, 50, 00, 8D, BE, 00, D0, EF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8981

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
592 KB (606,208 bytes)

The file angry birds provided through adscend media network cpa.exe has been seen being distributed by the following URL.