pdfcreatorsetup.exe

IronSource Ltd

The application pdfcreatorsetup.exe by IronSource has been detected as a potentially unwanted program by 7 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from soft.foxtab.com.
Publisher:
IronSource Ltd  (signed and verified)

MD5:
fb0940ebd828651f7cdda0cf0a5bdf20

SHA-1:
b5c82fc72bd97caa744c9de4091088c69ab8a6c7

SHA-256:
15d39df0d2b4962fc78d240318047fb07718024dff115a1903cc3ba9d03b8913

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 8:06:44 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:InstallCore-HF [PUP]
160126-1

Dr.Web
Adware.Downware.294
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.46782
10.0.0.5366

ESET NOD32
Win32/Kryptik.HAZ trojan
7.0.302.0

F-Prot
W32/InstallCore.F_2.gen
4.6.5.141

Reason Heuristics
PUP.ironSource.Installer (M)
16.2.14.0

VIPRE Antivirus
Threat.4778714
47068

File size:
585.4 KB (599,432 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pdfcreatorsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/8/2011 12:00:00 AM

Valid to:
11/7/2012 11:59:59 PM

Subject:
CN=IronSource Ltd, O=IronSource Ltd, STREET=Namal 36 suit 1, L=Tel Aviv-Yafo, S=IL, PostalCode=68033, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008E236034501AEA96AE96F0B0FD227271

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:+CmsgvD4TcUTxBEOBX05vNnyL+VKZgwbZ6524+uBKHEkJmI58+X:LiDAg805vNboZgMZaGAMEkJmMTX

Entry address:
0x119AE0

Entry point:
60, BE, 00, 00, 49, 00, 8D, BE, 00, 10, F7, FF, C7, 87, 10, B7, 0C, 00, 3C, 10, 30, 2E, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8663

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
552 KB (565,248 bytes)

The file pdfcreatorsetup.exe has been seen being distributed by the following URL.

Remove pdfcreatorsetup.exe - Powered by Reason Core Security