test.exe

File

appS marKet abC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application test.exe by appS marKet abC has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
appS marKet abC  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
0aa82d93024e05ef2435d45c78a71a3d

SHA-1:
6a9e8b30fde75c44ec11bd2b864c59637a4e3a8b

SHA-256:
322de111952ef00edc4b439410f5be209972a4c1fc8d95957d4c0afc0d3a50c2

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 12:25:53 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.31

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.15331

Dr.Web
infected with Trojan.OutBrowse.253
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

G Data
NSIS.Application.OutBrowse.AC
15.3.25

Malwarebytes
PUP.Optional.Outbrowse.Gen
v2015.03.31.12

McAfee
Artemis!DFF2CD820F24
5600.6810

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.31.0

Trend Micro House Call
Suspici.EE5406CB
7.2.90

File size:
1 MB (1,100,592 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar30-020644-724cc452-a429-46c4-8916-e7fa895957a2.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\test.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/26/2015 12:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=appS marKet abC, O=appS marKet abC, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
071709D5ED48BE5FC7460A34370E0E78

File PE Metadata
Compilation timestamp:
3/30/2015 3:06:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:zbSaE4mvt/7iJEhNw3WxBEaOS3hNcqSzrx:zbSv4mvlY6NSzl

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5479

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove test.exe - Powered by Reason Core Security