java_installer.exe

Plugin Update SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application java_installer.exe by Plugin Update SL has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The installer is marketed through download protals and search ads as the free Oracle Java Runtime but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Plugin Update SL  (signed and verified)

MD5:
4ddfec2e3d1ee56fafc163b269a07bc5

SHA-1:
f7217c53783a3931378f46a1ee48923c212d4e44

SHA-256:
d09322b38f7e65f3ed5f1dcc502477c3b468d503e6df0833b1cfed08b7318dc9

Scanner detections:
8 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/14/2024 2:33:45 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

AVG
Win32/DH{gRJ+UIEHeVRPFVGBFYEJHFOBE0GBDw}
2015.0.3383

ESET NOD32
Win32/SoftPulse.J potentially unwanted application
8.7.0.302.0

herdProtect (fuzzy)
2014.10.28.14

K7 AntiVirus
Unwanted-Program
13.183.13043

McAfee
Program.Socrydo
5600.7039

Reason Heuristics
PUP.PluginUpdateSL.O
14.8.14.4

VIPRE Antivirus
Threat.4783235
32186

File size:
1.3 MB (1,373,664 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\java_installer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2014 5:00:00 PM

Valid to:
6/12/2015 4:59:59 PM

Subject:
CN=Plugin Update SL, O=Plugin Update SL, L=Guia De Isora, S=Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
01438AF7C5B708CB0E497C84D028BF72

File PE Metadata
Compilation timestamp:
8/14/2014 1:04:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:XS6Cqp3hVbl9HxvLhgAFlMlCcmpElsnevdxK1NpZ:iqp3LDxdg4lMASl9dxKnv

Entry address:
0x3DF6

Entry point:
E8, 09, 27, 00, 00, E9, 7F, FE, FF, FF, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, F4, 95, 41, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, A8, 80, 41, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, F4, 95, 41, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00, 00, 00...
 
[+]

Entropy:
7.6727

Code size:
61.5 KB (62,976 bytes)

The file java_installer.exe has been seen being distributed by the following URL.

Remove java_installer.exe - Powered by Reason Core Security