5xn4xyuq.wdy

DIrect download gtt

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file 5xn4xyuq.wdy by DIrect download gtt has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
DIrect download gtt  (signed and verified)

MD5:
ea724e2aca0e6dd5765401de7cd4cb8f

SHA-1:
39099e43add0558918e136ceee3dd38e012e13b7

SHA-256:
67a89bbf688d755d59f1a4db1400bb13e01da39e9082a9b328cc4a622c015c85

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/28/2024 4:10:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.DIrectdo.Bundler (M)
16.5.13.6

File size:
611.8 KB (626,528 bytes)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\temp\5xn4xyuq.wdy

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/1/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=DIrect download gtt, O=DIrect download gtt, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0D62FBB580795F94946063DA41407834

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:JH5Nz4ajfhsvV5cc5/aFDMDalG+lcx0jhnpW/uCbaMPgAW9UUMLLHuoP5LGN:JH5NzjhYV5F4FDMeM+lHpW/5Pa9UxXO1

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove 5xn4xyuq.wdy - Powered by Reason Core Security