idcarddesigner.exe

DRPU ID Card Design Software

DRPU Software Pvt. Ltd.

The application idcarddesigner.exe by DRPU Software Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from drpu-id-card-design-software.software.informer.com.
Publisher:
DRPU Software Pvt. Ltd.   (signed by DRPU Software Pvt. Ltd.)

Product:
DRPU ID Card Design Software

Version:
8.5.3.2

MD5:
5214e055ca2eee919c344c30b93f6942

SHA-1:
8890e8bc94eca2e812bd34a263ff2f51e526aff4

SHA-256:
275dfe2afe04a02acdfe4280cb3d52db2e9c081f35918019490c6f24181a3ffe

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 12:16:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.14.9

File size:
5.2 MB (5,434,584 bytes)

Product version:
8.5.3.2

Copyright:
Copyright © 2007-2015, DRPU Software Pvt. Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\idcarddesigner.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/2/2015 8:00:00 AM

Valid to:
11/26/2015 7:59:59 AM

Subject:
CN=DRPU Software Pvt. Ltd., O=DRPU Software Pvt. Ltd., STREET=J-80 Patel Nagar - 1, L=Ghaziabad, S=UP, PostalCode=201001, C=IN

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2FD2587CD74244AC0E014757384D222F

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9986

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file idcarddesigner.exe has been seen being distributed by the following URL.

http://drpu-id-card-design-software.software.informer.com/.../

Remove idcarddesigner.exe - Powered by Reason Core Security