setup.exe

File

appS marKet abC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by appS marKet abC has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
appS marKet abC  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
e71bbb0794f727bd6c34737dadbed8ca

SHA-1:
6497a707594e08b893fcef02dfda9190c8782233

SHA-256:
a2547f7ca147b4733b981bac2c76adec4075882c013b213efd4b9cab57fab107

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/8/2024 10:10:07 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.29

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
PUP-gen [PUP]
150319-0

AVG
Downloader
2016.0.3156

Dr.Web
infected with Trojan.OutBrowse.225
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/28/2015

G Data
NSIS.Application.OutBrowse.AC
15.3.25

McAfee
Adware-OutBrowse.e
5600.6812

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.28.18

Trend Micro House Call
Suspici.F994BFB8
7.2.87

File size:
1 MB (1,100,920 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar28-180720-2524e926-a6d8-4335-a095-7cd0151b4e20.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/26/2015 12:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=appS marKet abC, O=appS marKet abC, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
071709D5ED48BE5FC7460A34370E0E78

File PE Metadata
Compilation timestamp:
3/28/2015 6:07:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:iMiy4IadS4ms5I6e66fEheKh1srF91dviyEkNPVAFdQqvY+CWNWcCwKwbgrKx1Bd:ibSaE4mvt/g8dvBEYhqv7+LrczXwUp

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5476

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove setup.exe - Powered by Reason Core Security