da658f0107a8967cc52eeea184ff8bd27dd188bd0c6ff194babf512332dcda4f

Sakysoft s.r.l.

The file da658f0107a8967cc52eeea184ff8bd27dd188bd0c6ff194babf512332dcda4f by Sakysoft s.r.l has been detected as a potentially unwanted program by 23 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Sakysoft s.r.l.  (signed and verified)

MD5:
e63db329e155352203214f4904db8953

SHA-1:
2cb0525306061eccf5e78a23583d9d17820e3a34

SHA-256:
da658f0107a8967cc52eeea184ff8bd27dd188bd0c6ff194babf512332dcda4f

Scanner detections:
23 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/25/2024 6:37:56 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.F
610

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.156.190

avast!
Win32:PUP-gen [PUP]
2014.9-150605

AVG
OutBrowse
2016.0.3088

Bitdefender
Application.Bundler.Outbrowse.F
1.0.20.780

Comodo Security
Application.Win32.OutBrowse.~A
18662

Dr.Web
Adware.Downware.1770
9.0.1.0156

ESET NOD32
Win32/OutBrowse (variant)
9.9997

Fortinet FortiGate
Riskware/NSIS_OutBrowse
6/5/2015

F-Secure
Application.Bundler.Outbrowse
11.2015-05-06_6

G Data
Application.Bundler.Outbrowse
15.6.24

IKARUS anti.virus
PUP.OutBrowse
t3scan.1.6.1.0

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
14.0.0.1935

Malwarebytes
PUP.Optional.OutBrowse
v2015.06.05.12

MicroWorld eScan
Application.Bundler.Outbrowse.F
16.0.0.468

NANO AntiVirus
Trojan.Win32.OutBrowse.csrlza
0.28.0.60475

Qihoo 360 Security
Win32/Virus.Downloader.ad6
1.0.0.1015

Quick Heal
TrojanDownloader.NSIS.OutBrowse.B
6.15.14.00

Reason Heuristics
Win32.Generic.Installer.Meta
15.6.5.0

Sophos
OutBrowse
4.98

Vba32 AntiVirus
Downloader.OutBrowse
3.12.26.3

VIPRE Antivirus
OutBrowse
30636

File size:
621.3 KB (636,160 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/4/2014 1:00:00 AM

Valid to:
3/4/2016 12:59:59 AM

Subject:
CN=Sakysoft s.r.l., O=Sakysoft s.r.l., STREET=Via Gorghi 6, L=Udine, S=UD, PostalCode=33100, C=IT

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00ECE0C7777AC73E48E3B63042EDCAEEB6

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:b4FyhCfsMntd1zdwVWyK1EzotWlj+kzVX0xp+lHTNo5uLMxHeXAkepYsq4x9:bIyhCfsMtpwof1EzotWln3M6VXopa4b

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9784

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)