beddhbajci.exe

Direct DoWnloaD gTt

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application beddhbajci.exe by Direct DoWnloaD gTt has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory.
Publisher:
Direct DoWnloaD gTt  (signed and verified)

Version:
2015.67.210.64

MD5:
a8f3d23572bae05d1343b31f58a34c4b

SHA-1:
52a0228d5028bf7bd7877b6d8a61cd51af3c6d0c

SHA-256:
7c91d5af422256440bf424aedd763fe3d720c97be2c0d591ed879171a63d625f

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/25/2025 3:52:38 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Outbrowse.Gen
8.3.1.6

avast!
Win32:OutBrowse-AE [PUP]
2014.9-150610

AVG
Downloader
2016.0.3083

Dr.Web
Trojan.OutBrowse.512
9.0.1.0161

ESET NOD32
Win32/OutBrowse.BZ potentially unwanted (variant)
9.11749

G Data
Win32.Adware.Outbrowse
15.6.25

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.9.12

Sophos
PUA 'OutBrowse Revenyou'
5.15

VIPRE Antivirus
Threat.4784459
40786

File size:
1.2 MB (1,223,728 bytes)

Product version:
2015.67.210.64

Copyright:
Copyright (C) 2015

Original file name:
20156721064.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\beddhbajci.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/3/2015 9:00:00 PM

Valid to:
1/27/2016 9:59:59 PM

Subject:
CN=Direct DoWnloaD gTt, O=Direct DoWnloaD gTt, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1A9527B3080B7A2460B95F1FDB83360E

File PE Metadata
Compilation timestamp:
6/7/2015 6:00:12 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:TcFlRDaQnXnef0dMXDZcK5aecJl+8Xdo5butH2LF8xehcrYR1j:IFLnXef0KTez+8NEbtB8xKcrYR1j

Entry address:
0xD991F

Entry point:
E8, 36, AE, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 5C, E2, 51, 00, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, 92, B0, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, 82, B0, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8, 89, 53, FC, 8B, 5B, 0C, 89, 45, E8, 89, 4D, EC, 83, FB, FE, 74, 5F, 8D, 49...
 
[+]

Code size:
986 KB (1,009,664 bytes)

Remove beddhbajci.exe - Powered by Reason Core Security