6636054573c4fc461e3d17bd7c73915d1eb981103fa0c29bd2eef7af58e80baf

Sakysoft s.r.l.

The file 6636054573c4fc461e3d17bd7c73915d1eb981103fa0c29bd2eef7af58e80baf by Sakysoft s.r.l has been detected as a potentially unwanted program by 22 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Sakysoft s.r.l.  (signed and verified)

MD5:
0756df93396ff3163244b0e4b64844d7

SHA-1:
6015a524cffa7d1ced76972adb9a2709a32ab947

SHA-256:
6636054573c4fc461e3d17bd7c73915d1eb981103fa0c29bd2eef7af58e80baf

Scanner detections:
22 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/19/2024 6:08:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
MemScan:Application.Bundler.Outbrowse.E
610

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.175.114

avast!
NSIS:OutBrowse-C [PUP]
2014.9-150604

AVG
Sakyso
2016.0.3088

Baidu Antivirus
Hacktool.Win32.Downloader
4.0.3.1564

Bitdefender
MemScan:Application.Bundler.Outbrowse.E
1.0.20.775

Dr.Web
Adware.Downware.3980
9.0.1.0155

ESET NOD32
Win32/OutBrowse
9.10482

F-Prot
Trojan!9d14
v6.4.7.1.166

F-Secure
MemScan:Application.Bundler.Outbrowse
11.2015-04-06_5

G Data
MemScan:Application.Bundler.Outbrowse
15.6.24

K7 AntiVirus
Trojan
13.183.13521

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1935

Malwarebytes
PUP.Optional.OutBrowse
v2015.06.04.11

MicroWorld eScan
MemScan:Application.Bundler.Outbrowse.E
16.0.0.465

NANO AntiVirus
Trojan.Nsis.Download.dcbgnj
0.28.2.62440

nProtect
MemScan:Application.Bundler.Outbrowse.E
14.09.29.01

Qihoo 360 Security
Win32/Virus.Downloader.277
1.0.0.1015

Quick Heal
Downloader.Agent.r5 (Not a Virus)
6.15.14.00

Reason Heuristics
Win32.Generic.Installer.Meta
15.6.4.23

VIPRE Antivirus
Trojan.Win32.Generic
33528

File size:
969.2 KB (992,448 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/4/2014 1:00:00 AM

Valid to:
3/4/2016 12:59:59 AM

Subject:
CN=Sakysoft s.r.l., O=Sakysoft s.r.l., STREET=Via Gorghi 6, L=Udine, S=UD, PostalCode=33100, C=IT

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ECE0C7777AC73E48E3B63042EDCAEEB6

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:ywYzbrTZBqf+3pR2/bg/0fPzWJkUH1acWio5U1e3ibM:efTjqAR++0nzWJkUVacjPYp

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9253

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)