download.exe

The application download.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This particular feature is designed to hijack the browser in an attempt to prevent other resources from modify the browser's search and home pages. The file has been seen being downloaded from ams1.ib.adnxs.com.
MD5:
71cffc69c8a0fc1f6952f4983c5df1b6

SHA-1:
97187a121dec5aff69ef1cf8517a5afb80516c83

SHA-256:
3158de575bd3caa946987eacccf5e1d502f8d13c38364431ae21d82381e22bcd

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/25/2024 11:12:05 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Outbrowse.lwasp
8.3.1.6

avast!
Win32:OutBrowse-G [PUP]
150602-1

IKARUS anti.virus
PUA.SearchProtect
t3scan.1.9.5.0

File size:
629 KB (644,136 bytes)

File type:
Executable application (Win16 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\download.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win16

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:XUhzELb2Ag+va0JpN8BAgSGEo+EKe/1HW+MhLRwbpzRJR1ue8PR5fc8vy4h:XUhzELb3PS0J7eAg+tPetHWhhLROpzRp

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9806

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file download.exe has been seen being distributed by the following URL.

Remove download.exe - Powered by Reason Core Security