ยังไม่ยืนยัน 380922.crdownload

SAFe dOwnload gtl

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file ยังไม่ยืนยัน 380922.crdownload by SAFe dOwnload gtl has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
VUKMF  (signed by SAFe dOwnload gtl)

Product:
VUKMF

Version:
3995.1561.1379.9773

MD5:
e95c98645d3d7ce19a581a18e371ed4f

SHA-1:
44f90b341ca08ddfcc83855757be45d4008e5354

SHA-256:
0fc030a8bf67671680e92d98d61e871782db434c01e0846dbe62af577ad16179

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/14/2024 6:06:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.SAFedOwn.Bundler (M)
16.3.14.20

File size:
741.7 KB (759,520 bytes)

Product version:
3995.1561.1379.9773

Copyright:
VUKMF

Trademarks:
VUKMF

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\ยังไม่ยืนยัน 380922.crdownload

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/28/2015 7:00:00 AM

Valid to:
1/28/2016 6:59:59 AM

Subject:
CN=SAFe dOwnload gtl, O=SAFe dOwnload gtl, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
52C30E423F995D6F84A108D53F985864

File PE Metadata
Compilation timestamp:
12/6/2009 5:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:yAAjAPEA1g8KPagimLK3z0dEIiVnLztFekAPrqwDrilz52ORHfc8vy4h2:yzo1g8yaOK3z0ZiVnfT4HilN1a86R

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9846

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)