random.exe.exe

Bon Don Jov

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application random.exe.exe by Bon Don Jov has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
Bon Don Jov  (signed and verified)

MD5:
ae4c3e6e8fc33c8aa86be13c3faa6413

SHA-1:
0aa2a268e083058731bb9ee383451259ae255875

SHA-256:
1cecefabc4d81b888a4ba00d6a4f60c8276834e0eb0ca379d488a9cdde506fc9

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 9:46:39 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.212.228

avast!
PUP-gen [PUP]
150101-1

AVG
Downloader
2016.0.3185

Dr.Web
Trojan.OutBrowse.54
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
2/27/2015

K7 AntiVirus
Unwanted-Program
13.1915113

Malwarebytes
PUP.Optional.OutBrowse
v2015.02.27.09

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

Reason Heuristics
PUP.Outbrowse
15.2.27.21

Sophos
PUA 'OutBrowse Revenyou'
5.11

Trend Micro House Call
Suspici.86E7A932
7.2.58

VIPRE Antivirus
Threat.4784459
37788

File size:
594.7 KB (609,008 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\6uf9x98k\random.exe.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/19/2014 3:36:12 AM

Valid to:
11/20/2015 3:36:12 AM

Subject:
CN=Bon Don Jov, O=Bon Don Jov, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112120D679EF1EE7D9572B904048A1A11800

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:nAQ+LlApLTAfyG1tBDlK3yTFO6FLDVP395dcasUB6ZUmFcHqlb:nAQ+OVI1tBcQOcL5VsUB62mGq

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9447

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove random.exe.exe - Powered by Reason Core Security