freefileviewerdmsetup.exe

Bitberry Software ApS

The application freefileviewerdmsetup.exe by Bitberry Software ApS has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from cdn1.freefileviewer.com.
Publisher:
Bitberry Software ApS  (signed and verified)

MD5:
4aece05331bcb25faa02ae5a2d9a73bb

SHA-1:
4c84b4c9e0c78e7b50fe3c219b5ab45393a0ffa4

SHA-256:
c6a59a830a82e2c195d977031e4b274b9f950777864e87fef091de68a27b9232

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 7:35:26 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.MulDrop5.47593
9.0.1.035

Reason Heuristics
PUP.Optional.Installer
15.2.4.9

File size:
754 KB (772,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\freefileviewerdmsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/20/2013 2:00:00 AM

Valid to:
11/19/2016 12:59:59 AM

Subject:
CN=Bitberry Software ApS, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Bitberry Software ApS, L=Holbæk, S=Alberta, C=DK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
23118AB330BEB5704ADCCE30BBB04D23

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:klF0OaCRzi78Zy3nkXo/eyCbDEgfvqsx52p2YfQjx1gcrEty7+gluFnXebeWQZGM:klFFaCRo4y0XoGyCXzfv9upVIxbA4+gg

Entry address:
0x9C40

Entry point:
13, 0E, 3B, 0B, 2A, 6B, 86, 8B, EE, E7, DC, B7, 52, 52, A4, C8, 06, 2D, AF, AC, DD, C5, 4F, 1F, 3A, 38, 20, 58, 0B, E6, 5B, 46, E4, 46, 09, F4, 2F, 8E, 0C, 1A, F4, 76, E0, A8, 9F, C6, 2F, 98, 1F, 96, F7, 3C, BD, 29, B3, 01, 52, E4, B4, 87, 02, 8C, C0, 6B, CC, 20, 7D, EC, 87, AA, C0, 44, B3, B7, E8, 3C, 92, 24, D4, 04, 6E, 9C, F7, 0B, C8, 08, B8, BF, 7E, C2, 32, F1, AB, BC, 45, 10, 46, 7F, 01, 11, 35, 46, 32, 54, BD, 65, 70, 7D, 43, 50, B8, 6A, D8, CB, D8, DF, 32, 34, 74, 83, 07, 86, 63, 5C, 66, 3F, 98, FF...
 
[+]

Code size:
37 KB (37,888 bytes)

The file freefileviewerdmsetup.exe has been seen being distributed by the following URL.

Remove freefileviewerdmsetup.exe - Powered by Reason Core Security