ttx tech universal wired controller ps3 pc driver.exe

diRECt DowNlOad gtT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application ttx tech universal wired controller ps3 pc driver.exe by diRECt DowNlOad gtT has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.down1702tech.info.
Publisher:
diRECt DowNlOad gtT  (signed and verified)

Version:
1918.15523.1280.5393

MD5:
df01cbb570de12f4e519c0ef33aaa7d4

SHA-1:
8e3d3cb9e0d24c4f27dd830d64899356b1b314a1

SHA-256:
f8dd345cab987a310d119e4c57d7fd2d16e7bdc61096d82f5f3dc3ecfecb4295

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/12/2024 4:30:48 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.05.24

AVG
Potentially harmful program Downloader.GLY
2014.0.4311

ESET NOD32
Win32/OutBrowse.CC potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
5/24/2015

McAfee
Artemis!10916E1EA735
5600.6756

NANO AntiVirus
Trojan.Win32.OutBrowse.drzddf
0.30.24.1636

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Outbrowse.Bundler
15.5.23.19

File size:
759.1 KB (777,352 bytes)

Product version:
1918.15523.1280.5393

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ttx tech universal wired controller ps3 pc driver.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/17/2015 8:00:00 PM

Valid to:
1/27/2016 6:59:59 PM

Subject:
CN=diRECt DowNlOad gtT, O=diRECt DowNlOad gtT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
667A43D07820F072234DDC81ADE311BF

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8KMlb16VaSJJQSvf16vTMb6orRzKU7Q1doBUqtmD/jw2fo3MWgmMqfc8vy4hJ:8KMzyJQkSTMb6+zk1doBUlD82w3ncH8R

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9633

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ttx tech universal wired controller ps3 pc driver.exe has been seen being distributed by the following URL.