unipdf_7975.exe

The application unipdf_7975.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from secure.ilandcachecdn.com.
MD5:
161cda1635741c911d1632ded58f5a29

SHA-1:
d41504b8098264d8d3704a72a8c657ce9a7e1f2f

SHA-256:
f3a6c4349a819c82dea42c413e51e7f1e634573039ac9c5898003b168ecc31c1

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/26/2024 11:50:40 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.InstallMonetizer
4.0.3.1656

Dr.Web
Adware.Downware.918
9.0.1.0127

ESET NOD32
Win32/InstallMonetizer.AT
10.9820

Malwarebytes
PUP.Optional.InstallMonetizer.A
v2016.05.06.11

McAfee
Artemis!161CDA163574
5600.6407

NANO AntiVirus
Riskware.Nsis.Toolbar.cvzrwd
0.28.0.59911

Reason Heuristics
PUP.InstallMonetizer.ET (M)
16.5.6.23

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.16504

Sophos
AppMonetizer Installer
4.98

Trend Micro House Call
TROJ_GEN.F47V0321
7.2.127

VIPRE Antivirus
InstallMonetizer
29386

File size:
337 KB (345,071 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\unipdf_7975.exe

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:DFJ0ahdssj7pJ59EuWn3Zyt5q2pd5A8Wwtf0fX+XogiRbzVSUfQH:FX7pB0JybJd5A8KeogKZQH

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8065

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file unipdf_7975.exe has been seen being distributed by the following URL.

Remove unipdf_7975.exe - Powered by Reason Core Security