windows_8_activator.exe

The application windows_8_activator.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from www.sugarsync.com.
MD5:
02d0332d51254d67f38186972545f4ca

SHA-1:
83d5d2c155dfb12919074fd2938e2a01446f48ce

SHA-256:
f64c2e929c6a85bf8d0a3a66b3526dc1979ba490e85e817a1defe299db440c30

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/24/2024 12:07:00 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Malware-gen
151205-4

Baidu Antivirus
Trojan.Win32.Injector
4.0.3.15129

ESET NOD32
multiple threats
7.0.302.0

Malwarebytes
PUP.Optional.OutBrowse
v2015.12.09.06

Qihoo 360 Security
QVM41.1.Malware.Gen
1.0.0.1077

File size:
1.9 MB (2,022,172 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
2/15/2015 12:00:37 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:B5QfEdXllq96JRaPtVituZyqvQ5fi9LH6+aRwvGYjCZuhVpHvi:B5QsllkuRQrituIqY5wu+aRw5e4hVtvi

Entry address:
0x10F4C

Entry point:
E8, 2D, 64, 00, 00, E9, 78, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Entropy:
7.9720  (probably packed)

Code size:
111.5 KB (114,176 bytes)

The file windows_8_activator.exe has been seen being distributed by the following URL.

Remove windows_8_activator.exe - Powered by Reason Core Security