bosch maxx 4 wfc 1262 user guide provided through pdfretriever.com.exe

Interactive Install

LiveSoftAction

The program utilizes the Appscion Download and Install manager, an adware distribution bundler from SIEN SA. The setup program includes ad-supported toolbars and utilities. The application bosch maxx 4 wfc 1262 user guide provided through pdfretriever.com.exe by LiveSoftAction has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the SIEN SuperInstall installer.
Publisher:
Live Soft Action S.R.L.  (signed by LiveSoftAction)

Product:
Interactive Install

Version:
1.0.11.0

MD5:
581527a5aad373b82833e74a304f0294

SHA-1:
95b0fbfe6db1fb6dc691aa04d1d3f61bc61a66f6

SHA-256:
c7f0437948c4bc637a88aff42590a142f2b8abde39b3d85c9095e8fa341a9a74

Scanner detections:
16 / 68

Status:
Adware

Explanation:
This is a modified installer that uses the Appscion to bundle adware.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/11/2024 2:39:07 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/GetNow.B
7.11.182.180

avast!
Win32:PUP-gen [PUP]
2014.9-141101

AVG
Generic_r
2015.0.3304

Dr.Web
Adware.Downware.3244
9.0.1.0305

ESET NOD32
Win32/GetNow (variant)
8.10654

F-Prot
W32/A-a4017d21
v6.4.7.1.166

G Data
Win32.Application.Getnow
14.11.24

IKARUS anti.virus
AdWare.Win32.GetNow
t3scan.1.8.3.0

K7 AntiVirus
Unwanted-Program
13.185.13866

Malwarebytes
PUP.Optional.GetNow
v2014.11.01.09

McAfee
LiveSoftAction
5600.6960

NANO AntiVirus
Riskware.Win32.Downware.dcolmc
0.28.6.62995

Reason Heuristics
PUP.Installer.LiveSoftAction.?
14.11.1.8

Sophos
Live Soft Action
4.98

VIPRE Antivirus
Appscion
34424

File size:
688.7 KB (705,216 bytes)

Product version:
1.0.11.0

Copyright:
(c) Live Soft Action S.R.L. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
SIEN SuperInstall

Language:
English (United States)

Common path:
C:\users\{user}\downloads\bosch maxx 4 wfc 1262 user guide provided through pdfretriever.com.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/5/2012 2:00:00 AM

Valid to:
6/6/2014 1:59:59 AM

Subject:
CN=LiveSoftAction, OU=SienAppNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=LiveSoftAction, L=Bucharest, S=functiune, C=RO

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
17E4CA22DB0D2CFD73BAACB9BD605BF7

File PE Metadata
Compilation timestamp:
4/17/2014 2:52:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:mSw/SZnFL6uIcjQ5ObQTQyr9nzZVvEiR5SY8ybqo1QQYH49Y/y90JT:62Qc8EQEslzvEcSod1QVN/yKT

Entry address:
0x197830

Entry point:
60, BE, 00, 40, 50, 00, 8D, BE, 00, D0, EF, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
592 KB (606,208 bytes)