chrono tales hack tool.exe

safe StORe BTW

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application chrono tales hack tool.exe by safe StORe BTW has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
PNXLO  (signed by safe StORe BTW)

Product:
PNXLO

Version:
9234.15830.1341.5579

MD5:
ec0aad8d412cce9476b6b354cb1333d5

SHA-1:
381a45a9c9f27e63bf362ca1867a1fdea6ad3a27

SHA-256:
bfbf7a835577b487f6ae8a3f252c18d508f3cda55527dfd2506c0d6724c4bff6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/20/2024 4:31:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.safeStOReBTW.Bundler (M)
15.8.30.13

File size:
606.3 KB (620,848 bytes)

Product version:
9234.15830.1341.5579

Copyright:
PNXLO

Trademarks:
PNXLO

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\chrono tales hack tool.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/30/2015 8:00:00 AM

Valid to:
1/28/2016 7:59:59 AM

Subject:
CN=safe StORe BTW, O=safe StORe BTW, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6108717788D723A1E9FEAD5857BE1D1E

File PE Metadata
Compilation timestamp:
12/6/2009 6:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:R2LdPiSwPZDaBveY7V1bP3s9qPkL6eRha92Ns5OFWU9QXq15jUCrYfdj:cLdPdgDap5V1bsCkL6GMUyMWeSqhYfdj

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9793

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove chrono tales hack tool.exe - Powered by Reason Core Security