appeonbrowser.exe

Appeon Multi-browser Plug-in

Appeon Corporation

The application appeonbrowser.exe, “Appeon Multi-browser Plug-in Setup ” by Appeon has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from khan.pro.ac.kr.
Publisher:
Appeon Corporation   (signed by Appeon Corporation)

Product:
Appeon Multi-browser Plug-in

Description:
Appeon Multi-browser Plug-in Setup

MD5:
366d102f9df45f310cace27c4ed91d54

SHA-1:
0964ebe9d7cde8146668f5fc4a079b5ae66d35a9

SHA-256:
6011a594c19a2c5edd152b76b54dc326be1037fec7b129a2214e6b4a8988705c

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/9/2025 7:26:48 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Detection.Undefined
9.0.1.05190

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.2.9

File size:
944.1 KB (966,744 bytes)

Product version:
1.1.1

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\appeonbrowser.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/14/2016 7:00:00 PM

Valid to:
9/29/2016 7:59:59 PM

Subject:
CN=Appeon Corporation, O=Appeon Corporation, L=ShenZhen, S=GuangDong, C=CN

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
763DA955BD2724D2CDCA32ADB8030889

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:/QiPoIbEk/gLMGpOSvRj/cc2UFnPTFaVYg+p6MX//h18jl:/9PoG/gLMaZjmQnPTHg+lb8Z

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9802

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file appeonbrowser.exe has been seen being distributed by the following URL.

http://khan.pro.ac.kr/appeon/weblibrary_ax/.../appeonbrowser.exe

Remove appeonbrowser.exe - Powered by Reason Core Security