install_reader11_uk_mssa_aaa_aih.exe

Adobe Reader

RICH MEDIA SYSTEMS INC.

The application install_reader11_uk_mssa_aaa_aih.exe by RICH MEDIA SYSTEMS INC has been detected as a potentially unwanted program by 21 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from adobe-reader.1800download.com and multiple other hosts.
Publisher:
RICH MEDIA SYSTEMS INC.  (signed and verified)

Product:
Adobe Reader

Version:
1.0.0.0

MD5:
a3c2687ec9dee3522556e838058cf9e5

SHA-1:
02653bcd253826e30c92dffd7065c93cf89bd1fa

SHA-256:
b442faf131399519f37410146fa325dab6313401265135f0294e692d2157cb02

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
5/15/2025 11:19:14 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.ME
656

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.OpenCandy
2015.04.20

AVG
OpenCandy
2016.0.3134

Bitdefender
Application.Bundler.ME
1.0.20.550

Clam AntiVirus
Win.Trojan.Agent-855157
0.98/21511

Dr.Web
Adware.Downware.10304
9.0.1.0110

ESET NOD32
Win32/OpenCandy.C potentially unsafe (variant)
9.11499

Fortinet FortiGate
Riskware/OpenCandy
4/20/2015

F-Secure
Application.Bundler.ME
11.2015-20-04_2

G Data
Application.Bundler.ME
15.4.25

K7 AntiVirus
Trojan
13.202.15641

Malwarebytes
PUP.Optional.OpenCandy
v2015.04.20.12

McAfee
Artemis!A3C2687EC9DE
5600.6790

MicroWorld eScan
Application.Bundler.ME
16.0.0.330

Panda Antivirus
PUP/OpenCandy
15.04.20.12

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.RICHMEDIASYSTEMS
15.5.8.23

Sophos
OpenCandy
4.98

Trend Micro House Call
Suspicious_GEN.F47V0413
7.2.110

VIPRE Antivirus
Sevas-S Installer
39500

File size:
415.7 KB (425,672 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\install_reader11_uk_mssa_aaa_aih.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/17/2015 9:00:00 AM

Valid to:
2/18/2016 8:59:59 AM

Subject:
CN=RICH MEDIA SYSTEMS INC., O=RICH MEDIA SYSTEMS INC., L=HENDERSON, S=Nevada, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3F87144C25AF8BCF29F29C5A1FEEF4BA

File PE Metadata
Compilation timestamp:
5/20/2013 8:53:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:6iucV6JgYaVNIsOVrXeLuWpHBDv9D50DM8TgYnMeph+S3f8rK0TaDEgDTI/LgpYd:6iuZavIBuZpv9gTXXoS3f2KwgfW4YrdX

Entry address:
0x331C

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 98, 92, 42, 00, E8, A8, 2E, 00, 00, A3, E4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 90, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, E0, 81, 42, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Entropy:
7.8859

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file install_reader11_uk_mssa_aaa_aih.exe has been seen being distributed by the following 30 URLs.

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXEwj 8WvauHEA0kxQ8PDK1GR/6cteQv c8/zOn/j1gwJgELkHteuKifDftnAg3cDbdT7zlGbRYhuIPmYXeVmPArn6XXR vpi733ufa7dPZkWlZ9cxzwwkTHTPlVix 18ko/CHoCzfGEulBipKwY2JFerJxJR4FIfq/FiM9LdzFfxEjiKPtFCUlfIXy2q4/.../44JDnzR1mZybWszMe3NHYc3iqT1OZzOh0Kgjx3zPWFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXBwj pXP7oQlssmV89fDKhEgqkP4CH4KEk5ib0oWJgytwGP0ykYrj2LTPllEZTcWmNEfuvCr50ybpq1oDEUx6avCX BlT1unm7j/.../QZpP5Z6xQn3rupKXmigoYL0AT4U9M2136aHnQUsoy1TsxdYHGS3jDB i98W2khJnayOQ7SgG1prZM3i6HBiJmvE8YwD6xyLUFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXBwj sXP7oQkEsnl0kPTqlHBzycteQv U8/zOh/jwnickFbk3kYqn9OHuuyxdSMWmeWLDzCr5uybhoz4WXBQaDoGzqBwX9v3GtzKyP oaf0nFA4p8ziUcCDSK1AX1/lck79jnxGWmdSq4KkZu0JTxEYro0JQpWbeyzByYjF4ybd093zqDlfWN F9ixkrxaXzjr3QuWxOE5TMeve4GkbnFWzZXkXql4zlRQr9Tvhhvyb6h/.../4 pDlww0tN3fFuG8S1prZM3i6HBiJmvE8YwD6xyLUFgF4

http://1800dcdn.blob.core.windows.net/dir195/wi/18/33/1/.../install_reader11_uk_mssa_aaa_aih.exe

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXBwj pXP7oQlssmV89fDKkEgqrOYjBvqA872/soWtgwJgELEfteu lfDPgkR0dcD eEKqtGbc90eg0m5TIGk7ErnutTlT8 3G7geeH94WNg2gIq5Y2iUcbCjXjW2Ip 4F8r3 vGGKYL/kHp5qidGZoOehjQElWa7GiHi9tc43EJREwyviwAC1mcoP4w 83DG2 skjE3/VuDoD5NNClLHtd1dO8D JnlRsf/921zQG6O7h zianB81U7sS7QXvguNKanCYyMekfEdF/.../44JDjzR1iZyyQ5y1Xz9KQOnGiVwGE3Oh0Kgjx3zPfFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxLzYtbB5LdpvzDj4D0jn45MP0ykYrj2LTDllEZTa2mNE LkErM90ewohJ/fUh6apiX5CET vX64jP3RpZrSk2lZ/.../44JDizR0nPHDAvGoG1prZM3i6HBiJmvE8YwD6xyLUFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXAwj 1RrjxCgghkkVxZmbzR1 xcteQv I253eq ysyl4pHaAW7erC/NXK ykYJZjzeTvTlTeRjlvtyz4WXAQaDqme4VQSiqnDmgfTVrNHRlWdNp5I7wF9BXmThU2pnn4Aj CHoWGGbRLhc2syiPTQNeuBrewoEcKX1XGh8e9zFZREkhrOyTXpxLcfg2q4/DWOos13HjvQvDpG3YoL3O2NXnMu8F/ssjRZW54v3nxuhOrh zianC8Qe5MWxUT2toZrTkC0qdbdRTsc3PXUx5rv7SAhqzRyz0ddWSnKiQlyv//Wmkl5xazDFuQVRhraOczH5KhCM2ZUuMFrugGmCFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXEwj /TeqjC1c0kw48PjylER3yY9XRt h152b0sCsrn8kFdE3mYLC/NXW20gIHbjfZWfusW780yathw86PDE b yXqWh r7Wm0yP/SqNPKyD0I5cRs3zoAASfzX3x0laxspUSnGSDIL 0Nmaiwbm8ZPfFnPRNMOa39RCU8asWNLBwonua9THJ6P8bg2q4/.../44JDizR0nPHDAvGoG1prZM3i6HBiJmvE8YwD6xyLUFgF4

http://adobe-reader.1800download.com/get_azure_file/.../zyn9np5iNEMJ1Xka6n3fHm6ykYNeiPVWby1E w9wr1izcWaDgmT9yS7BkX9qjvm3 fa7dPZm3FDs55ziVZIRjD Xix 18kv9Dn4WGGdRLxOw4TrMz0VPuBuegoEcKX0UHBtIZCNYkp 0M6mR3dxLcfz0IJwVQbn8Rme8649Vf3sKZqwOjkJzcr F oujV5MuZr21FL5ZqE2nSqsEZkCspPuAWvi8JuTkD4hYL5RTsc3O3Ux9Ka1Fllrjxyi1s9PUCbgBgfh98Onh1N0dzeG5HgfntPSMni6FBWC2q9iK1ehgXSVFgF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXBwj zXP7oQkEsml0kPDu1E1v4Y9bB9bpi/269qGl42dMcJgTtarHuezeuyxdSM2meGvusW780yasmnZKPDE b SXqDkT1vH /mf6SpNvSgzwIs55ziVJIRjH VGoq04A79WjwWWmLA UI2sy4PTYPY/o4LhgFIfuuFTojKYeLZEcwh LuEyQvatSmjr9gEyvv4w6a3u1nR5i7etD4MC0IioOvFqounBcH7I/1n1O7ZK5/hXr/.../jocjO2WhxO osB9FsbSphsePIWEEO01XzhrIVQn2OV1Srvc skh0ufXjCsnhBlZmKcie6ThjXif59YATz0CTSDQF4

http://adobe-reader.1800download.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxLzYtbB5LdpvzDj4D0jn45MP0ykYrn2LTf40l8bOGKGCei1E/Y9wbNym4WPDE b CXqSx p7CT4yOfa7dPem3Ee6dVpwQBQXy tCzp3ncUp/S/zUmjaSr9W2oS4YyUMMbMzJxNMOaz9RDwmLNzFZREkhrPmECQhfIXg2q4/.../3bJ4Mv6jqGiH35tnFiCdjbbVJV8RkbW0o8 imFwhpnB3z3dtOAXq Wlmm4YjvhAUmNGDFv2IG1prZM3i6HBiJmvE8YwD6xyLUFgF4

Latest 30 of 30 download URLs

Remove install_reader11_uk_mssa_aaa_aih.exe - Powered by Reason Core Security