powerpointviewer2010sp1-kb2460050-x86-fullfile-en-us-aoc-jd.exe

Microsoft powerpoint viewer

Sevas-S LLC

The application powerpointviewer2010sp1-kb2460050-x86-fullfile-en-us-aoc-jd.exe by Sevas-S has been detected as adware by 6 anti-malware scanners. This is a setup program which is used to install the application. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from www.joydownload.com.
Publisher:
Sevas-S LLC  (signed and verified)

Product:
Microsoft powerpoint viewer

Version:
1.0.0.0

MD5:
84fab37467403e51b777255b4c7421e3

SHA-1:
ae44d2bbca16bc048212d429f9d21b57a7ebc61d

SHA-256:
bbd5f042bc1cc32d6479c3172023b3ca50bba6a57eb6364594391c0c8667e8c5

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/25/2024 8:42:02 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Application.Win32.OpenCandy.~WD
17336

Dr.Web
Adware.Downware.1446
9.0.1.048

ESET NOD32
Win32/JoyDownloader
8.9094

Malwarebytes
PUP.Optional.OpenCandy
v2014.02.17.09

Reason Heuristics
PUP.SevasS.FF
14.8.7.20

Trend Micro House Call
TROJ_GEN.F47V1110
7.2.48

File size:
475.4 KB (486,800 bytes)

Copyright:
Copyright (C) Radiocom

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\powerpointviewer2010sp1-kb2460050-x86-fullfile-en-us-aoc-jd.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/23/2013 2:00:00 AM

Valid to:
2/23/2014 1:59:59 AM

Subject:
CN=Sevas-S LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sevas-S LLC, L=Kyiv, S=Kyivska oblast, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
527471E53862E2F90AB45ED4ACB8F4C2

File PE Metadata
Compilation timestamp:
5/20/2013 2:52:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:baCW7/vFhjs17FEUDTTup+Ts9PJYz5jtNcB+/TRfYN:FWTFhm7FjDHuzJYz5jtXTBYN

Entry address:
0x31B1

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, 34, 71, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 58, 92, 42, 00, E8, 90, 2E, 00, 00, A3, A4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 58, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, C0, 92, 40, 00, 68, A0, 81, 42, 00, E8, FB, 2A, 00, 00, FF, 15, 38, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, E9, 2A, 00, 00...
 
[+]

Entropy:
7.8572  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file powerpointviewer2010sp1-kb2460050-x86-fullfile-en-us-aoc-jd.exe has been seen being distributed by the following URL.