brothersoft_downloader_for_hp_photosmart_c4300_all_in_one_series_driver_software_9_0_0.exe

KORAM GAMES LIMITED

The application brothersoft_downloader_for_hp_photosmart_c4300_all_in_one_series_driver_software_9_0_0.exe by KORAM GAMES LIMITED has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dfiles.brothersoft.com.
Publisher:
KORAM GAMES LIMITED  (signed and verified)

MD5:
f32e09a98e8028aa114a55a655e36690

SHA-1:
a18d46dc76d8dc20d9974a0c8cc6e0ac9be58745

SHA-256:
ed2d980ee6e84447751ef6254d63268c1c7766a62b56977422219a4bbfdb4cbd

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 8:47:11 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.163.16

AVG
Generic
2015.0.3408

ESET NOD32
Win32/InstallCore.PQ (variant)
8.10125

K7 AntiVirus
Unwanted-Program
13.181.12775

Reason Heuristics
PUP.Optional.KORAMGAMESLIMITED.?
14.7.20.10

VIPRE Antivirus
Threat.4786140
31208

File size:
698.7 KB (715,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\brothersoft_downloader_for_hp_photosmart_c4300_all_in_one_series_driver_software_9_0_0.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/10/2014 1:00:00 AM

Valid to:
2/9/2017 12:59:59 AM

Subject:
CN=KORAM GAMES LIMITED, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=KORAM GAMES LIMITED, L=HongKong, S=HongKong, C=HK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
53B6BD34F6B702DEC3C291D72E678EEF

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:mGkFarr/1+PeVGRaCUj0Of7MHLBOObUNy+LeYPoX9uLmnQwUA4aDD:m3Fsr/1idab7MHgOoQZeefTD

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file brothersoft_downloader_for_hp_photosmart_c4300_all_in_one_series_driver_software_9_0_0.exe has been seen being distributed by the following URL.