audi a4 cabriolet user guide provided through pdfretriever.com.exe

Download Manager

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application audi a4 cabriolet user guide provided through pdfretriever.com.exe by LiveSoftAction has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Sien AppScion Download Manager installer.
Publisher:
LiveSoftAction  (signed and verified)

Product:
Download Manager

Version:
1.0.11.0

MD5:
28de1081e1f54aca7756a8a184d4fccd

SHA-1:
c9ea8197cfeed1be407703fb95e170380d10b68e

SHA-256:
de9ba46751f98d88ef39dad29a960f5c443a20f848d98be20dade8cc1ccafa3f

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 9:29:53 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.142.170

avast!
Malware-gen
2014.9-141030

AVG
Adware BundleApp_r.A
2015.0.3305

Comodo Security
Application.Win32.GetNow.C
18084

Dr.Web
Adware.Downware.2144
9.0.1.0303

ESET NOD32
Win32/GetNow.B potentially unwanted application
8.7.0.302.0

Fortinet FortiGate
Riskware/GetNow
10/30/2014

F-Prot
W32/A-a4017d21
v6.4.7.1.166

IKARUS anti.virus
AdWare.Downloader
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11721

Malwarebytes
PUP.Optional.LiveSoftAction.A
v2014.10.30.07

McAfee
LiveSoftAction!E3851D120DB2
5600.6961

NANO AntiVirus
Riskware.Win32.Downware.cwalwi
0.28.0.59048

Reason Heuristics
DownloadManager.LiveSoftAction.AA
14.10.30.19

Sophos
Live Soft Action
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10267

Trend Micro House Call
TROJ_GEN.F47V0325
7.2.303

VIPRE Antivirus
Appscion
28194

File size:
676.6 KB (692,864 bytes)

Product version:
1.0.11.0

Copyright:
(c) LiveSoftAction. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Sien AppScion Download Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\audi a4 cabriolet user guide provided through pdfretriever.com.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/5/2012 1:00:00 AM

Valid to:
6/6/2014 12:59:59 AM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
2/7/2014 2:03:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:aahUOV7c8TazefLtNUH56qcK/k+0sV8YBytOqDxy9087:aXOVw8TzLt1DvsKXtlDxyL7

Entry address:
0x18D860

Entry point:
60, BE, 00, D0, 4F, 00, 8D, BE, 00, 40, F0, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8970

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
580 KB (593,920 bytes)