pdfreadersetup.exe

The application pdfreadersetup.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.pdfreaderapps.com.
MD5:
b4a7145a5e5ae8fc9414b3bfbfaa9e15

SHA-1:
4efe6694857ac09e0ceadc76cac99080717d1e7f

SHA-256:
9ec33ecff769dcd4c60faed2f4549d64a48b9b2575e0419691fd0fa94f0a4aaa

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 11:21:09 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.133.40

Bkav FE
HW32.Laneul
1.3.0.4924

Comodo Security
ApplicUnwnt
17826

Dr.Web
Trojan.Packed.24524
9.0.1.0220

ESET NOD32
Win32/InstallCore.BQ (variant)
10.9456

F-Prot
W32/InstallCore.R.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.176.11239

Malwarebytes
v2016.08.07.10

Reason Heuristics
PUP.InstallCore.ENG (M)
16.8.7.22

Rising Antivirus
PE:Malware.InstallCore!6.4
23.00.65.16805

Trend Micro House Call
TROJ_GEN.F47V1002
7.2.220

Trend Micro
TROJ_GEN.R0CBC0OJE13
10.465.07

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
InstallCore
26726

File size:
665.6 KB (681,528 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\pdfreadersetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:jKLo4DMJfsLF1SHaKOu9MLuHeTvdpwclmZxOf/NnsypOMN6sKmAnkUeVpp/7LAWI:GMJfs5lqETjdlmZxOqy8c6POUeXpQWkN

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file pdfreadersetup.exe has been seen being distributed by the following URL.

Remove pdfreadersetup.exe - Powered by Reason Core Security