yz9tgdj7.exe

Cyberservices B.V.

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file yz9tgdj7.exe by Cyberservices B.V has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Cyberservices B.V.  (signed and verified)

MD5:
8fe34d6d1bfa78e2e03c793ac36b5039

SHA-1:
af46fd2ec31f1ea277169d3a4080ea19e96adc60

SHA-256:
4ec5e339f0c73204bcbc640167180568680fa47052e48d267479a2040ebf8bfe

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 11:32:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.CyberservicesBV (M)
16.2.13.13

File size:
452 KB (462,880 bytes)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\yz9tgdj7.exe.part

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/10/2014 2:00:00 AM

Valid to:
2/11/2016 1:59:59 AM

Subject:
CN=Cyberservices B.V., O=Cyberservices B.V., STREET=Keizersgracht 62-64 NL, L=Amsterdam, S=Nordholland, PostalCode=1015CS, C=NL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
797CAC4561E8B8B21910CD01E0002669

File PE Metadata
Compilation timestamp:
4/23/2014 10:32:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:TNEuhAmBzT9iYqg6YFE7Za348g2E1yJs+1GF6GH8VPflPrbZ3koHJhS59+T4reQN:TN3dzIYq6ENw48kJuVX1tHGCELydC

Entry address:
0x1A8D7

Entry point:
E8, AD, 48, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, DC, 8D, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40...
 
[+]

Entropy:
6.9740

Code size:
149 KB (152,576 bytes)

Remove yz9tgdj7.exe - Powered by Reason Core Security