ecdcabfbdgee.exe

SaFe install OPT

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application ecdcabfbdgee.exe by SaFe install OPT has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
aaa  (signed by SaFe install OPT)

Description:
bbb

Version:
2015.423.30.64

MD5:
50ca0c28b36dd9ff5f2b6215925c956b

SHA-1:
099e1deb1f0a4860aaec5b45fe8fb5c4d1fad614

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/16/2024 2:29:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.SaFeinst (M)
16.6.9.7

File size:
764 KB (782,376 bytes)

Product version:
2015.423.30.64

Copyright:
Copyright (C) 2016

Original file name:
20154233064.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\ecdcabfbdgee.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/21/2015 8:00:00 AM

Valid to:
1/28/2016 7:59:59 AM

Subject:
CN=SaFe install OPT, O=SaFe install OPT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
234B90B3CEA9DDF3A22FA56FE435E852

File PE Metadata
Compilation timestamp:
4/23/2015 11:00:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:MLob/KIiOTuJglw6zHl8awiu+tctg8lCvOHZ03hmRQYUC8QnRhittndwbX5Plaa:vb/KIiOTuJz6DlGiuLg8lCOZchcQZQn7

Entry address:
0x7A77B

Entry point:
E8, 4A, A9, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, E0, 57, 49, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 68, 50, 49, 00, C9, C2, 08, 00, B8, 0F, 5C, 48, 00, A3, 78, 1F, 4B, 00, C7, 05, 7C, 1F, 4B, 00, 05, 53, 48, 00, C7, 05, 80, 1F, 4B, 00, B9, 52, 48, 00, C7, 05, 84, 1F, 4B, 00, F2, 52, 48, 00, C7, 05...
 
[+]

Entropy:
6.6117

Code size:
590.5 KB (604,672 bytes)

Remove ecdcabfbdgee.exe - Powered by Reason Core Security