{blocked}.exe

SavePs

The application {blocked}.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from 113.171.224.173 and multiple other hosts.
Publisher:
SavePs

Product:
SavePs

Version:
1.0

MD5:
70f790263f98a8deecd8010d152a2e1a

SHA-1:
88f4fe8a37e3ba683546a2a451268136e3572fe2

SHA-256:
0eb26f7d1cc5fc3d4f03b08079bb60101486343b3e61087d8c0803a01431556c

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/25/2024 11:11:54 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3280

Baidu Antivirus
Trojan.Win32.MsiDrop
4.0.3.141124

ESET NOD32
Win32/OutBrowse.BH
8.10772

IKARUS anti.virus
Trojan-Dropper.Win32.Msidrop
t3scan.1.8.3.0

Malwarebytes
PUP.Optional.SavePass.A
v2014.11.24.09

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

File size:
10.1 MB (10,566,494 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\savepass_20141120.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:m0GIpxWKvUoosz7qNSnj5eDaFqJv9nWiqeMUhnqpFKso1J5:kIpt1nSSHiv9WBeLq5k

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9994

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file {blocked}.exe has been seen being distributed by the following 2 URLs.

http://113.171.224.173/.../SavePass_20141120.exe

Remove {blocked}.exe - Powered by Reason Core Security