hack tool 2015 v1.28.exe

tiKI TAkA

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application hack tool 2015 v1.28.exe by tiKI TAkA has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The file has been seen being downloaded from get.0133g.info.
Publisher:
JWGVE  (signed by tiKI TAkA)

Product:
JWGVE

Version:
6604.1565.846.4995

MD5:
6d367f6cb223acb4075d913291783a09

SHA-1:
fdf7325a80645d6f206e4e5a0c62228b72e914b8

SHA-256:
f40858a0299de319c04cf580d8ef96cc84cf35ba02fa4631e4f42d62aecfe65a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/19/2024 12:34:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.8.16.15

File size:
635.3 KB (650,496 bytes)

Product version:
6604.1565.846.4995

Copyright:
JWGVE

Trademarks:
JWGVE

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\hack tool 2015 v1.28.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/26/2015 2:00:00 AM

Valid to:
12/18/2015 12:59:59 AM

Subject:
CN=tiKI TAkA, O=tiKI TAkA, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6C9AA41091271D60E493F99B663EA5E0

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:BfjKguqDbprmBUrFHwZGGLB0tWOqfpaeSS/hUWBOLfc8vy4h0:BfjKrqDBmBUxut0tW/sS5UWBOo86b

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file hack tool 2015 v1.28.exe has been seen being distributed by the following URL.

http://get.0133g.info/.../1433508946/1433508946?07998589338Z15rKSg6aDQyNCo5H1s0KjExKDYjZD0rLSgqKx5lOi4eZHJlWGVkW2Veal09QVhaYyAqJ1FsZ2weKScqKyksIi8oViolKTAhXmBpYmZhZlw0QFxbYiIvKFRoZmMdLSgpLS4tJSsnTSkpKi8jUDVIWlpiHS0oS2xsZCUrJykoLC0cLy1OMScpLx5kW2ZrOioyH3FgaDgo

Remove hack tool 2015 v1.28.exe - Powered by Reason Core Security