6_offer_17.exe

Free DJVU Reader

Media Freeware

The application 6_offer_17.exe, “This installer database contains the logic and data required to install Free DJVU Reader.” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from bg.softoware.net and multiple other hosts.
Publisher:
Media Freeware

Product:
Free DJVU Reader

Description:
This installer database contains the logic and data required to install Free DJVU Reader.

Version:
1.0.0

MD5:
2d10fabd0013671293deef1a419b74dc

SHA-1:
ddb193fbb5cafbb8befede524f02d8d483f915b8

SHA-256:
4c5ce0c6ae791e2c1d932f042d155adb75f824be5c3fb163e99d292a14809025

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:51:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.K
14.9.30.13

File size:
2.7 MB (2,864,751 bytes)

Product version:
1.0.0

Copyright:
Copyright (C) Media Freeware

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\6_offer_17.exe

File PE Metadata
Compilation timestamp:
10/18/2012 11:04:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:51RyRaUs2cSnewLBCFu5PrQ4jL5tQ5F1DjxUnljMSyvksvT82xtoL:/RqsnSnewFxPH5tQ5HDGnlA9812x+L

Entry address:
0xAB509

Entry point:
E8, 25, B9, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, F0, 33, DB, 3B, F3, 75, 1E, E8, CF, 44, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, CB, EB, FF, FF, 83, C4, 14, 8B, C6, E9, C2, 00, 00, 00, 57, 39, 5D, 0C, 77, 1E, E8, AB, 44, 00, 00, 6A, 16, 5E, 53, 53, 53, 53, 53, 89, 30, E8, A7, EB, FF, FF, 83, C4, 14, 8B, C6, E9, 9D, 00, 00, 00, 33, C0, 39, 5D, 14, 66, 89, 06, 0F, 95, C0, 40, 39, 45, 0C, 77, 09, E8, 7C, 44, 00, 00, 6A, 22, EB, CF, 8B, 45, 10, 83, C0, FE, 83, F8, 22, 77...
 
[+]

Entropy:
7.4398

Code size:
884.5 KB (905,728 bytes)

The file 6_offer_17.exe has been seen being distributed by the following 11 URLs.

http://bg.softoware.net/get-free-djvu-reader.html?ir=1

&onid=18497&oid=3001-18497_4-76098610&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=design/pdf&topicbrcrm=&pid=14502500&mfgid=10301275&merid=10301275&ctype=dm&cval=NONE&devicetype=desktop&pguid=d6a75add06ff536197f571dd&viewguid=dB80@bvisBMWSFbHMAJjs-EuojX4DEqnugYc&destUrl=http://mediafreeware.com/.../djvureader_setup.exe

Remove 6_offer_17.exe - Powered by Reason Core Security