deluge+bittorrent+client_1.0.exe

Digitainment AG

The application deluge+bittorrent+client_1.0.exe by Digitainment AG has been detected as adware by 8 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from piratebay.com.
Publisher:
Digitainment AG  (signed and verified)

MD5:
30245653e5b3bf8ad7bdc3da26a47af6

SHA-1:
c613879d5aea7ac107eb5c66d9b63c1fb8acf534

SHA-256:
9e069f66fde96ab7d1b0926ef6c569a738251824e079c60ceab7c5ce0c83f0e1

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/25/2024 4:30:43 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.OutBrowse
2016.0.2966

ESET NOD32
Win32/DownloadGuide (variant)
9.9594

G Data
Win32.Application.DownloadGuide
15.10.24

herdProtect (fuzzy)
2015.10.5.3

Malwarebytes
PUP.Optional.Rspark
v2015.10.05.03

Reason Heuristics
PUP.DigitainmentAG (M)
15.8.18.22

Trend Micro House Call
TROJ_GEN.F47V0317
7.2.278

VIPRE Antivirus
Trojan.Win32.Generic
27744

File size:
441.6 KB (452,208 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\deluge+bittorrent+client_1.0.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/9/2013 1:00:00 AM

Valid to:
12/10/2015 12:59:59 AM

Subject:
CN=Digitainment AG, O=Digitainment AG, STREET=Schulstrasse 7, L=Würenlingen, S=Aargau, PostalCode=5303, C=CH

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
646A1470B7987C344845192F6B828D61

File PE Metadata
Compilation timestamp:
3/7/2014 10:23:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:K6tjk73xdNHSVvmtZhZY3Iog58Qk1K9BUhc8I2F6GH8VPflPrGGu1fDPB+T4reQ8:KRlSYZnVog585mUZuVX1cDPwELwl

Entry address:
0x19496

Entry point:
E8, 9E, 48, 00, 00, E9, 89, FE, FF, FF, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, AC, 6D, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0...
 
[+]

Code size:
143.5 KB (146,944 bytes)

The file deluge+bittorrent+client_1.0.exe has been seen being distributed by the following URL.

Remove deluge+bittorrent+client_1.0.exe - Powered by Reason Core Security