angry birds provided through adscend media network cpa.exe

Interactive Install

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application angry birds provided through adscend media network cpa.exe by LiveSoftAction has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer. The file has been seen being downloaded from stapi.maxrevinstaller.com.
Publisher:
Live Soft Action S.R.L.  (signed by LiveSoftAction)

Product:
Interactive Install

Version:
1.0.11.0

MD5:
992a7f9845c5f5a0817da8d6d2562fc7

SHA-1:
96401425e0f4f15578a3c12211c413efd5ce340f

SHA-256:
b61a4345b77f9d08a43083a95c2a87ef1b39945b864d2b535b4cdbbb0952fd9b

Scanner detections:
24 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:37:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.670831
372

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
Adware/Downware.M.4
7.11.150.80

avast!
PUP-gen [PUP]
2014.9-160129

AVG
Adware BundleApp_r.Q
2017.0.2850

Bitdefender
Application.Generic.670831
1.0.20.145

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Downware-629
0.98/19788

Comodo Security
Application.Win32.GetNow.D
18552

Dr.Web
Adware.Downware.3244
9.0.1.029

ESET NOD32
Win32/GetNow.J potentially unwanted application
10.7.0.302.0

F-Prot
W32/A-a4017d21
v6.4.7.1.166

F-Secure
Application.Generic.670831
11.2016-29-01_6

G Data
Win32.Application.Getnow
16.1.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.185.13853

Malwarebytes
PUP.Optional.LiveSoft
v2016.01.29.07

McAfee
Program.LiveSoftAction
5600.6506

MicroWorld eScan
Application.Generic.670831
17.0.0.87

NANO AntiVirus
Riskware.Win32.Downware.dcceei
0.28.2.60990

Reason Heuristics
PUP.Sien.LiveSoftAction.Bundler (M)
16.1.29.7

Sophos
PUA 'Live Soft Action' (of type Adware)
5.14

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9356

VIPRE Antivirus
Threat.4794174
29418

File size:
691.2 KB (707,816 bytes)

Product version:
1.0.11.0

Copyright:
(c) Live Soft Action S.R.L. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\downloads\angry birds provided through adscend media network cpa.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/4/2012 2:00:00 PM

Valid to:
6/5/2014 1:59:59 PM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
5/6/2014 5:00:33 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:b+wcFVeJnv/jKrJ91xZkNsvxJrPkhlLNzUTGMUfxIaJXKy90pj:Swc/eJnv2rr1xONQxl6lLNAT0f96yqj

Entry address:
0x1981F0

Entry point:
60, BE, 00, 40, 50, 00, 8D, BE, 00, D0, EF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8971

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
596 KB (610,304 bytes)

The file angry birds provided through adscend media network cpa.exe has been seen being distributed by the following URL.