ppviewer.exe

REDACCENIR SL

The application ppviewer.exe by REDACCENIR SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from dm.portalprogramas.com.
Publisher:
REDACCENIR SL  (signed and verified)

MD5:
e83e4bf1f89b1c0c7d0315c2594a44c5

SHA-1:
35b710b1826ea43a298d0d98ec805bf23d4c4060

SHA-256:
6cc2839a3f6203ce4aaa561ddd3d139b8b3079d4d1af1ff5b43ff8d162e20122

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 7:20:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.REDACCENIR (M)
16.3.6.15

File size:
1.1 MB (1,128,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ppviewer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/22/2011 9:00:00 PM

Valid to:
12/22/2012 8:59:59 PM

Subject:
CN=REDACCENIR SL, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=REDACCENIR SL, L=Terrassa, S=Barcelona, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
71215C0E2FF8F33A61438B1BB7D0D7D3

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:oFc6BxrLx8NZzcuqNPO6JmEtAa4VH/WV6nGTnHbajQZzRLSTo24s+VJDHrMQgR/4:+PGZ+O6JLtAa4VYMGEez0TvYEoH

Entry address:
0xC1E50

Entry point:
55, 8B, EC, 83, C4, F0, B8, 18, 55, 44, 00, E8, DB, DA, FF, FF, 2E, C7, 55, 25, 6B, 87, 33, 69, 94, 03, A1, CA, EA, 6B, EF, 19, 98, DD, F1, 9D, 7A, 8B, D0, CD, 08, 7A, AE, 45, AB, 4F, 98, 22, 02, E7, 6C, 2A, EA, B5, 94, 3A, 5C, 1D, DB, 07, 4F, 58, AD, 18, 5B, 86, 81, 88, B4, 02, 4D, 05, B6, 1D, 3D, FB, 2B, D0, 09, 09, EE, 18, A5, 0D, B3, E9, 2C, 73, F0, 21, 33, 9A, 4E, B9, 01, 6E, 0F, 28, 36, 8F, 57, CD, F6, AA, 44, B7, A1, D6, 36, 33, 94, 16, C9, E3, A4, 5A, 58, 6A, 35, A2, FC, C4, 17, 11, 7F, EF, A0, 1B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
787 KB (805,888 bytes)

The file ppviewer.exe has been seen being distributed by the following URL.

Remove ppviewer.exe - Powered by Reason Core Security