labview+free+download+ful_10924_i129744555_il345.exe

PDFCreator

AITI Strim CONSULTING, TOV

The application labview+free+download+ful_10924_i129744555_il345.exe, “PDFCreator is the easy way of creating PDFs.” by AITI Strim CONSULTING, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
pdfforge GmbH  (signed by AITI Strim CONSULTING, TOV)

Product:
PDFCreator

Description:
PDFCreator is the easy way of creating PDFs.

Version:
2.2.2

MD5:
e0b589bab206afec84643f017650d1c5

SHA-1:
1df64b0cde73b8517c46fd472bf4e5a98187c971

SHA-256:
d4dadcc324c982d215bb121a8055f15a98ff3f80455f5838376746769ceaa6f0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 4:20:06 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize.AITIStri.Installer (M)
16.4.23.9

File size:
2.1 MB (2,151,704 bytes)

Product version:
2.2.2

Copyright:
© pdfforge GmbH

Original file name:
PDFCreator-2_2_2_1066-setup-pdfforge.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\labview+free+download+ful_10924_i129744555_il345.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/11/2016 7:00:00 AM

Valid to:
1/11/2017 6:59:59 AM

Subject:
CN="AITI Strim CONSULTING, TOV", OU=IT, O="AITI Strim CONSULTING, TOV", STREET="Bud. 53-55, vul.Pochainynska", L=Kyyiv, S=Kyyiv, PostalCode=04080, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5A7A1CB365BD8EA3567456D3B8166630

File PE Metadata
Compilation timestamp:
1/26/2016 12:52:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:Dz+9VjCC6GTJGSS30/gZ6cRzo7npfziM2fpmXY:Dz6E1ei30YZ6zf+M2xN

Entry address:
0x2A745A

Entry point:
68, 72, 23, 61, 65, E8, 63, 06, FF, FF, ED, 30, DF, 15, DE, 21, D1, 24, 12, 85, 8A, DE, 20, F0, 7F, 54, 33, 38, B6, 93, DF, 27, C7, 3B, C4, 3D, 8D, 25, 10, 9D, DA, 03, 74, 5F, C3, 03, D5, E0, A1, 6D, 80, 8C, 76, 7A, 77, 32, C5, 56, 40, BF, B8, 1D, 03, 48, 31, 0D, 78, 47, 7B, DD, B8, AA, 9B, B4, E1, 5D, 5F, 26, 69, 63, 68, 0F, 20, 74, 5F, 31, 6D, E3, D9, 54, 49, 57, 85, 6A, FA, 54, 2D, 84, 51, 7A, 2D, A1, 0D, D8, CB, 2D, CC, 52, 1D, 57, 68, 5C, D5, 7F, 05, 7E, F8, E5, E3, D3, A1, 6D, 08, F9, BA, 85, A5, 86...
 
[+]

Code size:
2 MB (2,135,040 bytes)