free-mkv-to-mp4-setup.exe

The application free-mkv-to-mp4-setup.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from software-files-a.cnet.com.
MD5:
b180ff46667b8ed7459fd3b148ec3331

SHA-1:
78f83208b678032cb85a3f5cf2e096e8db4daf6a

SHA-256:
87097c3259a01d661dec243dbefb6d9da9e7d5dc0475d68414e6593472bd3cda

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/24/2024 7:57:00 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/OutBrowse.F.5
7.11.123.138

avast!
Win32:PUP-gen [PUP]
2014.9-140105

AVG
MalSign.Generic
2014.0.3611

Bkav FE
W32.Clod6a3.Trojan
1.3.0.4613

Comodo Security
Application.Win32.Agent.~BRO
17556

Dr.Web
Adware.Downware.1336
9.0.1.0362

ESET NOD32
Win32/OutBrowse
7.9252

Fortinet FortiGate
W32/OutBrowse.D
12/21/2013

K7 AntiVirus
Trojan
13.175.10735

Kaspersky
not-a-virus:Downloader.NSIS.Agent
14.0.0.4587

Malwarebytes
PUP.Optional.Smart
v2013.12.21.01

McAfee
Artemis!B180FF46667B
5600.7274

NANO AntiVirus
Trojan.Win32.OutBrowse.crupsg
0.28.0.57029

Reason Heuristics
Unnamed.Threat.18
14.3.2.16

Sophos
Generic PUA HI
4.96

Trend Micro House Call
TROJ_GEN.R047H07HO13
7.2.362

Vba32 AntiVirus
Downloader.Agent
3.12.24.3

VIPRE Antivirus
OutBrowse
25108

File size:
572.3 KB (586,004 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\free-mkv-to-mp4-setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:bd2ArFBW4zcfmQT5XxrxuiABXpf3PKk9hxsesWj7TlalYAyBMJB:bd3rFB5jK5XdlAbfXhllalhyaL

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9754

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file free-mkv-to-mp4-setup.exe has been seen being distributed by the following URL.

Remove free-mkv-to-mp4-setup.exe - Powered by Reason Core Security