setup.exe

The application setup.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download1285.mediafire.com.
MD5:
6d8899b5c4e2ddadcf66d879b6b84a2d

SHA-1:
b7953ab3556092df00d39551076f69aea79c3c29

SHA-256:
381a8fb5daebc78b29ccadda6bffabed7bb384a03e939cf4a9ddbdab96c7e0e5

Scanner detections:
18 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/24/2024 10:29:59 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

AVG
MalSign.OutBrowse
2015.0.3559

Baidu Antivirus
HackTool.Win32.OutBrowse
4.0.3.14218

Comodo Security
Application.Win32.OutBrowse.~A
17809

Dr.Web
Adware.Downware.1770
9.0.1.049

ESET NOD32
Win32/OutBrowse (variant)
8.9440

Fortinet FortiGate
Riskware/NSIS_OutBrowse
2/18/2014

IKARUS anti.virus
not-a-virus:Downloader.NSIS
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.176.11205

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
14.0.0.4291

Malwarebytes
PUP.Optional.OutBrowse
v2014.02.18.06

McAfee
Artemis!6D8899B5C4E2
5600.7215

NANO AntiVirus
Trojan.Win32.OutBrowse.csrlza
0.28.0.57630

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Sophos
OutBrowse
4.97

Trend Micro House Call
TROJ_GEN.R0C1H07AN14
7.2.49

Vba32 AntiVirus
Downloader.OutBrowse
3.12.24.3

VIPRE Antivirus
OutBrowse
26594

File size:
616 KB (630,735 bytes)

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:JMFyhCfsMntd1zdwVWyK1EzotWlj+kzVX0xp+lHTNo5uLMxHeXAkepYsq4W:JcyhCfsMtpwof1EzotWln3M6VXopa4W

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9783  (probably packed)

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security