adobe flash player for desktops 11.5.50.exe

Yes Apps

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application adobe flash player for desktops 11.5.50.exe by Yes Apps has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Yes Apps  (signed and verified)

MD5:
4d480a88c065b8c49f6c592254655786

SHA-1:
75ac217e14e28e9d57b61ec581b4065811680c30

SHA-256:
4a39e26e52c30113cdaa3767a723b041ed5967cad0afb90cee8bbe6ac79df44d

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 3:44:53 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
7.0.302.0

McAfee
Adware-OutBrowse.c
5600.6923

Reason Heuristics
PUP.YesApps.f
14.12.10.9

Sophos
PUA 'OutBrowse' (of type Adware)
5.08

File size:
567.6 KB (581,240 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe flash player for desktops 11.5.50.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/19/2014 1:31:49 AM

Valid to:
11/20/2015 1:31:49 AM

Subject:
CN=Yes Apps, O=Yes Apps, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172AA41CC838C994475C56326A04F3761

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8ujoplWgr+C2SnoIpSNe3bg2RVP5UOx+l6:8raC2SndYYLl5U29

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9681

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file adobe flash player for desktops 11.5.50.exe has been seen being distributed by the following URL.

Remove adobe flash player for desktops 11.5.50.exe - Powered by Reason Core Security