adobe_flash_setup.exe.exe

Yes Apps

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application adobe_flash_setup.exe.exe by Yes Apps has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Yes Apps  (signed and verified)

MD5:
5211970160a3a496e6126d2f1ef45402

SHA-1:
d36045592cc43708244328ef15386675b9d910a8

SHA-256:
814b2422e9e8967c9d5dd84ffc7d6af5619b98f444124166968efd90fc5bc406

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 12:32:00 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.203.58

Dr.Web
Trojan.OutBrowse.59
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BQ potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
1/20/2015

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.191.14691

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.20.03

McAfee
Program.Adware-OutBrowse.d
16.8.708.2

NANO AntiVirus
Trojan.Win32.OutBrowse.dlwssj
0.30.0.64448

Reason Heuristics
PUP.Installer.Outbrowse
15.1.20.3

Trend Micro House Call
Suspici.202D3B0F
7.2.20

Vba32 AntiVirus
Downloader.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4657539
36666

File size:
581.4 KB (595,320 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\adobe_flash_setup.exe.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/31/2014 2:21:42 PM

Valid to:
11/20/2015 4:31:49 AM

Subject:
CN=Yes Apps, O=Yes Apps, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F73F4D345BF2CECF93F6A6F1DA99EDD3

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:twDtR+ITQAqKZLTfuNmxBCs65F/aVTmo/Vlm8QixYN0v:tYtRjTQAqKJTmNOM5F/aVy6+HI

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9742

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file adobe_flash_setup.exe.exe has been seen being distributed by the following URL.

Remove adobe_flash_setup.exe.exe - Powered by Reason Core Security