installation.exe

Direct Download Gtt

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application installation.exe by Direct Download Gtt has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.file28desktop.com.
Publisher:
Direct Download Gtt  (signed and verified)

MD5:
046c300006f919a240f8c2e55b032c5a

SHA-1:
0ab785de88025fe218b34b373fd55b70e1d7b629

SHA-256:
b6928a4d2102035a072d882601354fba92296d9468eb330f1a6da39634edbf34

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/15/2024 5:32:36 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.1
6507467

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.16

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.217.124

avast!
OutBrowse-GY [PUP]
150129-1

AVG
Potentially harmful program Downloader.DJP
2014.0.4257

Bitdefender
Gen:Variant.Application.Bundler.Outbrowse.1
1.0.20.370

Comodo Security
Application.Win32.AltBrowse.HY
21422

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Outbrowse
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/15/2015

F-Secure
Gen:Variant.Application.Bundler
11.2015-15-03_1

G Data
Gen:Variant.Application.Bundler.Outbrowse
15.3.25

K7 AntiVirus
Trojan
13.200.15263

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Gen:Variant.Application.Bundler.Outbrowse.1
16.0.0.222

NANO AntiVirus
Trojan.Win32.OutBrowse.dnpjkd
0.30.0.296

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.15.16

Sophos
Generic PUA JE
4.98

Trend Micro House Call
Suspici.BD67879B
7.2.74

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4150696
38050

File size:
580.4 KB (594,360 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installation.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/5/2015 7:00:00 AM

Valid to:
1/28/2016 6:59:59 AM

Subject:
CN=Direct Download Gtt, O=Direct Download Gtt, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1368B5662E01BF764D0663326565A2F0

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Oz1R4GRoxkXn0U2wIBW0D9OfgIstnA8uz1VuQ1y:Ozf4nin0UKQ0bFnA8uuH

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9657

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installation.exe has been seen being distributed by the following URL.

Remove installation.exe - Powered by Reason Core Security