pdfreadersetup.exe

IronSource Ltd

The application pdfreadersetup.exe by IronSource has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from soft.foxtab.com.
Publisher:
IronSource Ltd  (signed and verified)

MD5:
208b9e0c342df94f9c4b580b4a728699

SHA-1:
c36016654d2b5f62e0ff2243fec7a066fe69ba64

SHA-256:
7192f8351e1c70bcc9bb062cd016dee291fe319312ae08d4c4cdde887b5fced6

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 2:09:00 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.27502
5813571

avast!
Win32:InstallCore-HF [PUP]
160118-1

AVG
Adware Generic5.EAS
2015.0.4489

Clam AntiVirus
Adware.Installcore
0.98/21318

Dr.Web
Adware.Downware.294
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.27502
10.0.0.5366

ESET NOD32
Win32/Kryptik.JPT trojan
7.0.302.0

F-Prot
W32/InstallCore.B.gen
4.6.5.141

F-Secure
Variant.Adware.Graftor
5.15.21

Norman
Gen:Variant.Adware.Graftor.27502
18.01.2016 17:20:53

VIPRE Antivirus
Threat.4150696
46794

File size:
572.9 KB (586,632 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\pdfreadersetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/8/2011 12:00:00 AM

Valid to:
11/7/2012 11:59:59 PM

Subject:
CN=IronSource Ltd, O=IronSource Ltd, STREET=Namal 36 suit 1, L=Tel Aviv-Yafo, S=IL, PostalCode=68033, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008E236034501AEA96AE96F0B0FD227271

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:l0UPZE2j4leLc4VG0wwpFgA0XAY62PtcA/Ol3R8N4iT:l0URE2jHLB7XPaARE1/OluSiT

Entry address:
0x118A00

Entry point:
60, BE, 00, 20, 49, 00, 8D, BE, 00, F0, F6, FF, C7, 87, 10, 87, 0C, 00, 43, 95, DB, C1, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
540 KB (552,960 bytes)

The file pdfreadersetup.exe has been seen being distributed by the following URL.

Remove pdfreadersetup.exe - Powered by Reason Core Security