1431331312.exe

Click Yes

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application 1431331312.exe by Click Yes has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Click Yes  (signed and verified)

Version:
2015.511.80.64

MD5:
ae66a24ef52d4bbbd52fb2756c837c30

SHA-1:
19b6518f4f2802bbf5a9f3509081bd8e1fa5c55a

SHA-256:
64d0559b4762ddede3d9842604b50ef58a222624c0d030830912e07b68806bea

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/29/2024 5:50:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.9.3.15

File size:
928.2 KB (950,480 bytes)

Product version:
2015.511.80.64

Copyright:
Copyright (C) 2015

Original file name:
20155118064.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\1431331312.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
4/7/2015 1:46:38 PM

Valid to:
12/8/2015 7:13:03 PM

Subject:
CN=Click Yes, O=Click Yes, L=DUBLIN, C=IE

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
3BFBE10CD0A09BE9

File PE Metadata
Compilation timestamp:
5/11/2015 1:00:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:KTH545yanLM/rNJdFye6XszrmnpUmOSc4YsahMnDnfhhCX9+:kzCLM/rNwe6XszrmewYsaWnDnfhhCX9+

Entry address:
0x26540

Entry point:
E8, 55, AD, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 10, 88, 4B, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 68, 80, 4B, 00, C9, C2, 08, 00, B8, DF, 1D, 43, 00, A3, 88, 4F, 4D, 00, C7, 05, 8C, 4F, 4D, 00, D5, 14, 43, 00, C7, 05, 90, 4F, 4D, 00, 89, 14, 43, 00, C7, 05, 94, 4F, 4D, 00, C2, 14, 43, 00, C7, 05...
 
[+]

Entropy:
6.5836

Code size:
729.5 KB (747,008 bytes)

Remove 1431331312.exe - Powered by Reason Core Security