keyloggerprofree_setup.exe

RSPARK LIMITED LIABILITY COMPANY

The application keyloggerprofree_setup.exe by RSPARK LIMITED LIABILITY COMPANY has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from freekeyloggerpro.com.
Publisher:
RSPARK LIMITED LIABILITY COMPANY  (signed and verified)

MD5:
95e46b611b198ff8e62545f6a780c9d4

SHA-1:
e16edc3a2cc99761e19b99ae02afc89ab4513ac6

SHA-256:
61de6f310ce27bf036b382c603732c6949801b2c213acb1024820456e6e9778e

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/26/2024 7:14:26 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.01.26

Avira AntiVirus
APPL/Downloader.Gen
7.11.205.14

AVG
Generic
2016.0.3219

Dr.Web
Trojan.Packed.28592
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.192.14746

McAfee
Adware-OutBrowse.e
5600.6875

Reason Heuristics
PUP.Installer.RSPARKLIMITEDLIABILITYCOMPANY
15.1.25.11

Trend Micro House Call
Suspici.84A1176B
7.2.25

VIPRE Antivirus
Threat.4823950
36694

File size:
575 KB (588,840 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\keyloggerprofree_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
8/20/2014 11:42:44 AM

Valid to:
8/21/2015 11:42:44 AM

Subject:
E=billing@rspark.com, CN=RSPARK LIMITED LIABILITY COMPANY, O=RSPARK LIMITED LIABILITY COMPANY, L=Seattle, S=Washington, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214776E87F6F533491BA6962DED798AED3

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:grFMBD+WZTRVhEZzJNnrbPoaVO6XlIgbYgOBWW8ggMz:grFMpJ2DoaVO6JbwAgV

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9715

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file keyloggerprofree_setup.exe has been seen being distributed by the following URL.

Remove keyloggerprofree_setup.exe - Powered by Reason Core Security