codecperformersetup.exe

Installer

PPCTechSoft Inc.

This is the Performersoft setup installer. The application codecperformersetup.exe by PPCTechSoft has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the InstallBrain installer. The file has been seen being downloaded from www.softologicsa.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
PPCTechSoft Inc.  (signed and verified)

Product:
Installer

Version:
15.9.28.27

MD5:
d1ec355bf79f6784648ef4202b4bf03b

SHA-1:
b0a81129a5e88057276b5ad2a437337e3742c206

SHA-256:
b2016259526fe46f02dfa12394e4e7da41ad91e37d1e572822415da9e0bb3360

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 10:09:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Performersoft (M)
16.8.5.17

File size:
726.8 KB (744,248 bytes)

Product version:
15.9.28.27

Copyright:
Copyright 2012

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\codecperformersetup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
3/29/2013 7:18:32 PM

Valid to:
3/29/2016 7:18:32 PM

Subject:
CN=PPCTechSoft Inc., O=PPCTechSoft Inc., L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0782D382C7277D

File PE Metadata
Compilation timestamp:
8/1/2013 11:07:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:yxVXDUakDljM2iuOTST/5kxyIWVW5NVptjiq5LpCmOrrMjpn1uuWNHfu8dPXuMfT:wDUjViZTghw5NLYWLphOrrMj3unNG8hl

Entry address:
0xF0A6

Entry point:
E8, 7B, 5F, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 20, EF, 42, 00, 00, 75, 18, E8, C6, 57, 00, 00, 6A, 1E, E8, 10, 56, 00, 00, 68, FF, 00, 00, 00, E8, DC, 50, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 20, EF, 42, 00, FF, 15, 68, 40, 42, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 44, EF, 42, 00, 74, 0D, 53, E8, 66, 41, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 61, 09, 00, 00, 89, 30, E8, 5A, 09, 00, 00, 89...
 
[+]

Entropy:
7.8018  (probably packed)

Code size:
136.5 KB (139,776 bytes)

The file codecperformersetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove codecperformersetup.exe - Powered by Reason Core Security