autodesk autocad 2014 iso full version for windows 64bit 32bit.exe

SaFe SofTWare SLl

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application autodesk autocad 2014 iso full version for windows 64bit 32bit.exe by SaFe SofTWare SLl has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
KBUCP  (signed by SaFe SofTWare SLl)

Product:
KBUCP

Version:
848.1564.1352.2309

MD5:
304be4e04fd7a03563d2fdbf2242ce9b

SHA-1:
a5ef28522bda7c86b0bda2d808f3152c4a901eef

SHA-256:
f189bd4e67eeed37117c8a1a4e35d44e5694ccfd145a8208091dbbe0b367c066

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/23/2024 9:28:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.10.14.8

File size:
633.8 KB (648,984 bytes)

Product version:
848.1564.1352.2309

Copyright:
KBUCP

Trademarks:
KBUCP

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\autodesk autocad 2014 iso full version for windows 64bit 32bit.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/25/2015 6:00:00 PM

Valid to:
1/27/2016 4:59:59 PM

Subject:
CN=SaFe SofTWare SLl, O=SaFe SofTWare SLl, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
59BA06BDD5FE8AD6611178F07F528856

File PE Metadata
Compilation timestamp:
12/5/2009 3:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:Lh7gSlpZJ587gdOD0xTVQkaM0L4mCcpzTfc8vy4hu:LhESFJ5c7DaVQXsozA863

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9815

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)