viber-for-windows-pc.exe

AVSoftware EOOD

The software installer uses the StartInstall.com download manager which bundles additional adware offers (toolbars and utilities such as the SafeSearch toolbar) during setup. The application viber-for-windows-pc.exe by AVSoftware EOOD has been detected as adware by 5 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore monetization download manager to download additional third party applications that may be unwanted by the user. The file has been seen being downloaded from dsu7x9k8c43un.cloudfront.net.
Publisher:
AVSoftware EOOD  (signed and verified)

MD5:
708a9a2390c076a3fe3fa8d67aba5411

SHA-1:
f62f04405083836afdeeb5a772bc9e88d5af2b9e

SHA-256:
2fd6c37538982cdc50c9ce8ed6052a950c7b80b8f85c06e35cc9e4e9b21a202c

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
12/27/2024 12:48:26 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.2909

K7 AntiVirus
Riskware
13.212.17779

Malwarebytes
PUP.Optional.SoftM8
v2015.12.01.11

Reason Heuristics
PUP.AVSoftware EOOD.AVSoftwareEOOD (M)
15.12.1.11

Sophos
Install Core Click run software (PUA)
4.98

File size:
960 KB (983,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\viber-for-windows-pc.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/5/2013 3:30:00 AM

Valid to:
6/4/2016 4:29:59 AM

Subject:
CN=AVSoftware EOOD, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=AVSoftware EOOD, L=Sofia, S=Sofia, C=BG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EB840FECC84AE6DCA7A92109E2314ED

File PE Metadata
Compilation timestamp:
9/9/2014 12:57:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:K2V9uSWpPUQOiydvby0yzz3k12grzM+lylqqdEyB2uH+6qSegpynQc:K6ufPUQNGqngv2Yqjsp6qSegYnT

Entry address:
0x3004E0

Entry point:
60, BE, 00, 70, 61, 00, 8D, BE, 00, A0, DE, FF, C7, 87, 18, CA, 26, 00, 07, 10, C2, 4A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.9210

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
936 KB (958,464 bytes)

The file viber-for-windows-pc.exe has been seen being distributed by the following URL.

Remove viber-for-windows-pc.exe - Powered by Reason Core Security