realtek high definition audio codec driver for 2000_xp_2003 v2.74.exe

Cyberservices B.V.

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application realtek high definition audio codec driver for 2000_xp_2003 v2.74.exe by Cyberservices B.V has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from downloadguidefactory.blob.core.windows.net.
Publisher:
Cyberservices B.V.  (signed and verified)

MD5:
fe9ffb17c1a0f16c26338aa4e39b738f

SHA-1:
6036a806ef2e0cb96a50c12e45237a1766f6264e

SHA-256:
c90161b22a5559071cda125f0523b2b1e2ac9645800c2fc7b5400bdf7d816370

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 4:02:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.7.28.5

File size:
456.6 KB (467,536 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\realtek high definition audio codec driver for 2000_xp_2003 v2.74.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/10/2014 7:00:00 AM

Valid to:
2/11/2016 6:59:59 AM

Subject:
CN=Cyberservices B.V., O=Cyberservices B.V., STREET=Keizersgracht 62-64 NL, L=Amsterdam, S=Nordholland, PostalCode=1015CS, C=NL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
797CAC4561E8B8B21910CD01E0002669

File PE Metadata
Compilation timestamp:
6/2/2014 3:30:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:+yR6TH0tFToG8t0gSyu3TLpbuVX1Hc50lmC7u8y:9eEgB8fpiVF80h7up

Entry address:
0x1C854

Entry point:
E8, A2, 48, 00, 00, E9, 89, FE, FF, FF, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 0C, DE, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF...
 
[+]

Entropy:
6.8978

Code size:
170.5 KB (174,592 bytes)

The file realtek high definition audio codec driver for 2000_xp_2003 v2.74.exe has been seen being distributed by the following URL.