ecacabfbdfbje.exe

SaFe SoftwaRe sLL

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application ecacabfbdfbje.exe by SaFe SoftwaRe sLL has been detected as adware by 18 anti-malware scanners. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. It is also typically executed from the user's temporary directory.
Publisher:
SaFe SoftwaRe sLL  (signed and verified)

Version:
2015.420.180.64

MD5:
22bd66ec05b224e3cc46986aac794959

SHA-1:
7f7131bcf344fe7e275d40324967cbef22819a05

SHA-256:
a996a08131ecc7aca2bb909259d4a431997c8c7737921843cc2084d4d898ac99

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/19/2024 10:56:05 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.04.21

AVG
OutBrowse
2016.0.3133

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.15421

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Outbrowse-19
0.98/21511

Dr.Web
Trojan.OutBrowse.328
9.0.1.0111

ESET NOD32
Win32/OutBrowse.BX potentially unwanted (variant)
9.11477

G Data
Win32.Adware.Outbrowse
15.4.25

herdProtect (fuzzy)
2015.7.22.13

McAfee
Artemis!CA0958B759BC
5600.6696

MicroWorld eScan
Gen:Variant.Adware.Mikey.11942
16.0.0.609

NANO AntiVirus
Trojan.Win32.OutBrowse.dqnzjj
0.30.20.1219

nProtect
Trojan/W32.PornoAsset.782376
15.05.08.01

Reason Heuristics
Threat.Outbrowse.SaFeSoftwaResLL
15.4.21.3

Sophos
OutBrowse Revenyou
4.98

Vba32 AntiVirus
Signed-Adware.Outbrowse
3.12.26.3

VIPRE Antivirus
OutBrowse
39364

File size:
764 KB (782,376 bytes)

Product version:
2015.420.180.64

Copyright:
Copyright (C) 2015

Original file name:
201542018064.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\ecacabfbdfbje.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/5/2015 8:00:00 AM

Valid to:
1/28/2016 7:59:59 AM

Subject:
CN=SaFe SoftwaRe sLL, O=SaFe SoftwaRe sLL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
48BED2CF9FCBEF623FB88AA3FDFAD281

File PE Metadata
Compilation timestamp:
4/21/2015 2:00:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:GLob/KIiOTuJglw6zHl8awiu+tctg8lCvOHZ03hmRQYUC8QnRhit+odwkN5Plag:9b/KIiOTuJz6DlGiuLg8lCOZchcQZQna

Entry address:
0x7A77B

Entry point:
E8, 4A, A9, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, E0, 57, 49, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 68, 50, 49, 00, C9, C2, 08, 00, B8, 0F, 5C, 48, 00, A3, 78, 1F, 4B, 00, C7, 05, 7C, 1F, 4B, 00, 05, 53, 48, 00, C7, 05, 80, 1F, 4B, 00, B9, 52, 48, 00, C7, 05, 84, 1F, 4B, 00, F2, 52, 48, 00, C7, 05...
 
[+]

Entropy:
6.6118

Code size:
590.5 KB (604,672 bytes)

Remove ecacabfbdfbje.exe - Powered by Reason Core Security