aipackagechainer.exe

PDF to Excel Converter Free

Rspark LLC

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application aipackagechainer.exe, “This installer database contains the logic and data required to install PDF to Excel Converter Free.” by Rspark has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
RS  (signed by Rspark LLC)

Product:
PDF to Excel Converter Free

Description:
This installer database contains the logic and data required to install PDF to Excel Converter Free.

Version:
1.0.0

MD5:
c42e733e60a854ee131fd7f64484f89d

SHA-1:
59ca09c9e5f53cbf6b9fd2bca737d9a3a860b126

SHA-256:
cc6cfb3bad41b732309717870eaa7a751a842c7b70042d3b3d5a667bb1e1d2c1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:24:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.11.7.1

File size:
279.6 KB (286,288 bytes)

Product version:
1.0.0

Copyright:
Copyright (C) 2015 RS

Original file name:
aipackagechainer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\rs\pdf to excel converter free\prerequisites\aipackagechainer.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/30/2015 8:00:00 AM

Valid to:
3/30/2016 7:59:59 AM

Subject:
CN=Rspark LLC, OU=Sam Cohen Brown, O=Rspark LLC, STREET=2929 1st Avenue, STREET=405, L=Seattle, S=WA, PostalCode=98121, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009B5883FE4688D09B024556FD8F95EF29

File PE Metadata
Compilation timestamp:
3/13/2014 9:42:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:+A57mG1hkFHFzb4WBaLzAreTQ8nWdJF5AJxj:D1mgqFzk+a/ArcQJJIz

Entry address:
0x17382

Entry point:
E8, B6, 58, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, 8B, 54, 24, 04, 8B, 4C, 24, 08, F7, C2, 03, 00, 00, 00, 75, 3C, 8B, 02, 3A, 01, 75, 2E, 0A, C0, 74, 26, 3A, 61, 01, 75, 25, 0A, E4, 74, 1D, C1, E8, 10, 3A, 41, 02, 75, 19, 0A, C0, 74, 11, 3A, 61, 03, 75, 10, 83, C1, 04, 83, C2, 04, 0A, E4, 75, D2, 8B, FF, 33, C0, C3, 90, 1B, C0, D1, E0, 83, C0, 01, C3, F7, C2, 01, 00, 00, 00, 74, 18, 8A, 02, 83, C2, 01, 3A, 01, 75, E7, 83, C1, 01, 0A, C0, 74, DC, F7, C2, 02, 00, 00, 00, 74, A4, 66, 8B, 02, 83, C2, 02...
 
[+]

Entropy:
6.2970

Code size:
153.5 KB (157,184 bytes)

Remove aipackagechainer.exe - Powered by Reason Core Security