bleach blade battlers 2 iso.exe

AV TRADE UKRAINE LLC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application bleach blade battlers 2 iso.exe by AV TRADE UKRAINE has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.down1208life.info.
Publisher:
AV TRADE UKRAINE LLC  (signed and verified)

MD5:
9d35ad8a46878891aaedc4cb5e2b0914

SHA-1:
105a579790cfc7bfa89e530ee5c5f2ff5d9d9c26

SHA-256:
bcff0581500c0fce5d33ed5e095e86a3e555ff17de36d578c0093d436cf84e9c

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 7:49:01 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.209.46

AVG
Downloader
2016.0.3203

Comodo Security
Application.Win32.AltBrowse.HY
21026

Dr.Web
infected with Trojan.OutBrowse.92
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BT potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
2/10/2015

F-Secure
Adware.SwiftBrowse.CX
5.13.68

K7 AntiVirus
Trojan
13.194.14915

Malwarebytes
PUP.Optional.OutBrowse
v2015.02.10.08

NANO AntiVirus
Trojan.Win32.OutBrowse.dnpjkd
0.30.0.65070

Reason Heuristics
PUP.Outbrowse
15.2.14.11

VIPRE Antivirus
Threat.4150696
36694

File size:
581.2 KB (595,112 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bleach blade battlers 2 iso.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/28/2014 7:00:00 PM

Valid to:
12/29/2015 6:59:59 PM

Subject:
CN=AV TRADE UKRAINE LLC, O=AV TRADE UKRAINE LLC, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
17461AF707CFE5F83DB478FF0FA80E94

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:7sCDz/tvze2QYy0S0fbaAhdQK2cYLg0RBAde5vFegiSp:7sIbtvze2QYAADQtcD7edFegj

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9668

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file bleach blade battlers 2 iso.exe has been seen being distributed by the following URL.

Remove bleach blade battlers 2 iso.exe - Powered by Reason Core Security