photopospro_setup.exe

PowerOfSOftware Ltd.

The application photopospro_setup.exe by PowerOfSOftware has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.downloadthat.com and multiple other hosts.
Publisher:
PowerOfSOftware Ltd.  (signed and verified)

MD5:
822237cf6e42d2a5e7a08f21c16e57af

SHA-1:
93f8bb9619e798119ba7b2e01257f495245e28db

SHA-256:
d48a7a37db6863019aad6490b51976e9d735a164fbfb7bade39d6013aa03aea0

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 5:38:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.PowerOfSOftware.R
14.7.27.14

Rising Antivirus
PE:Malware.Perflogger!6.48D
23.00.65.14119

File size:
78 MB (81,740,664 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\photopospro_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/23/2013 1:00:00 AM

Valid to:
12/24/2014 12:59:59 AM

Subject:
CN=PowerOfSOftware Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PowerOfSOftware Ltd., L=Rison Le-Ziyyon, S=ISRAEL, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
410A249080C78CC9486E96E29E654E9B

File PE Metadata
Compilation timestamp:
10/23/2011 12:27:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:AjUG6akpmR6W7ZXKMOYF4toVnStydO8cdmzsPUIesnkzwihfirR7qc6421fzwY1i:LekpmR6WRnFHVYeMdyo8hfiF2c64urg

Entry address:
0x29452

Entry point:
55, 8B, EC, 6A, FF, 68, 88, C8, 42, 00, 68, E0, 8C, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 38, C1, 42, 00, 33, D2, 8A, D4, 89, 15, 20, 39, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 1C, 39, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 18, 39, 48, 00, C1, E8, 10, A3, 14, 39, 48, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 33, 14, 00, 00, FF, 15, 0C, C1, 42, 00, A3, 20, 3E, 48, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
171 KB (175,104 bytes)

The file photopospro_setup.exe has been seen being distributed by the following 2 URLs.

Remove photopospro_setup.exe - Powered by Reason Core Security