visa application form of the people's republic of china(pdf version with effect from september 1, 20

Avi Podavsky

The file visa application form of the people's republic of china(pdf version with effect from september 1, 20, “Installer for WinterSoft” by Avi Podavsky has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Tarma Installer installer.
Publisher:
WinterSoft  (signed by Avi Podavsky)

Product:
WinterSoft

Description:
Installer for WinterSoft

Version:
2013.10.21.1806

MD5:
9113d99976a6ac0a71217ce14afbc127

SHA-1:
a76e81db190b5f984be63fd62047f6a2cb7d0d65

SHA-256:
a54053e2832907bb169cbc76d2680885a80fc07a5dfc6a626171d4ba19b7e965

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
4/19/2024 1:30:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.1.11

File size:
303.8 KB (311,072 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2013 WinterSoft

Original file name:
TSULoader.exe

Installer:
Tarma Installer

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\visa application form of the people's republic of china(pdf version with effect from september 1, 2013).exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/19/2012 5:30:00 AM

Valid to:
12/20/2013 5:29:59 AM

Subject:
CN=Avi Podavsky, O=Avi Podavsky, STREET=Rabina 8, L=Tel Aviv, S=Tel Aviv, PostalCode=69395, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5D3DDFA793E1D90EDC661CF311773BF6

File PE Metadata
Compilation timestamp:
3/12/2013 2:21:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9599

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)