Policedecriture Font(Aarvark Cafe) Downloader.exe

The application Policedecriture Font(Aarvark Cafe) Downloader.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.policedecriture.com.
MD5:
4b13741f97ec1ce5c7229b4463726aa0

SHA-1:
f9df3ba8ad2f4f5e1b63680e05e46e4e743450e5

SHA-256:
0ae4235b36cd0c25e7dfd3b94c5d174bbccff207b81c2e8b0dc01358a0b6fe0a

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 7:04:59 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
APPL/ClickRun.fqh
7.11.142.76

AVG
InstallCore
2015.0.3509

Comodo Security
Application.Win32.ClickRun.A
18076

Dr.Web
Adware.InstallCore.69
9.0.1.0100

ESET NOD32
Win32/InstallCore.AT (variant)
8.9658

NANO AntiVirus
Trojan.Win32.InstallCore.csswtr
0.28.0.59048

Panda Antivirus
PUP/MultiToolbar.A
14.04.10.01

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14408

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.26.0

VIPRE Antivirus
Click run software
28184

File size:
1 MB (1,079,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\policedecriture font(aarvark cafe) downloader.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wQ/1RDxmcFxZibnjDXd57gBnSGiAgnc0teTyl7tZsXXzLjk9/g2:FRDxmcnwbnjbd5UBmHnc0t8ydt6XjLjF

Entry address:
0xCAA90

Entry point:
55, 8B, EC, 83, C4, F0, B8, B4, CA, 40, 00, E8, E4, DB, FF, FF, 42, 04, 89, 03, B0, 01, 5E, 5B, C3, 8B, 50, 04, 8B, 08, 89, 0A, 89, 51, 04, 8B, 15, E0, 75, 45, 00, 89, 10, A3, E0, 75, 45, 00, C3, 53, 56, 57, 55, 51, 8B, F1, 89, 14, 24, 8B, E8, 8B, 5D, 00, 8B, 04, 24, 8B, 10, 89, 16, 8B, 50, 04, 89, 56, 04, 8B, 3B, 8B, 43, 08, 8B, D0, 03, 53, 0C, 3B, 16, 75, 14, 8B, C3, E8, B7, FF, FF, FF, 8B, 43, 08, 89, 06, 8B, 43, 0C, 01, 46, 04, EB, 16, 8B, 16, 03, 56, 04, 3B, C2, 75, 0D, 8B, C3, E8, 9A, FF, FF, FF, 8B...
 
[+]

Entropy:
6.9547

Developed / compiled with:
Microsoft Visual C++

Code size:
826 KB (845,824 bytes)

The file Policedecriture Font(Aarvark Cafe) Downloader.exe has been seen being distributed by the following URL.