download.exe

SaFE clIck LoL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application download.exe by SaFE clIck LoL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
TXVPK  (signed by SaFE clIck LoL)

Product:
TXVPK

Version:
5275.15117.1380.9715

MD5:
b6a67963a488c2362229636905a38bda

SHA-1:
f8ada1dc9e69fbc347a84b5bf8d32ddd8aab6284

SHA-256:
a0316c485f2c08d0b3b6260fdfc7c11243920a9daa805be0aed6f91d07a29279

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/27/2024 5:00:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.10.2.18

File size:
315.6 KB (323,160 bytes)

Product version:
5275.15117.1380.9715

Copyright:
TXVPK

Trademarks:
TXVPK

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\download.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/31/2015 2:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=SaFE clIck LoL, O=SaFE clIck LoL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6A4D214C072FB3F4C288346142D6738B

File PE Metadata
Compilation timestamp:
12/6/2009 12:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:IFJ0hQsE1skGhDH8qMgOmBoxIuJfkSjcvU2aP+:9QHzGlH88MIuJfkq6UT2

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6450

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove download.exe - Powered by Reason Core Security