cbacabfibbdi.exe

Trusted Download TYY

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application cbacabfibbdi.exe by Trusted Download TYY has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Trusted Download TYY  (signed and verified)

Version:
2015.28.1111.10

MD5:
17987e077914dfa867ef66b0f2a660fa

SHA-1:
d0bed30ef17f2d357e824b0fe9be097f7f2da8c8

SHA-256:
bde7820cc9bab48654e6d7febd019428e4f42a32bde7f7c0ded6d884022814a0

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
1/12/2025 11:38:31 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.TrustedDownloadTYY (M)
16.2.21.8

File size:
824.2 KB (843,984 bytes)

Product version:
2015.28.1111.10

Copyright:
Copyright (C) 2015

Original file name:
201528111110.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\cbacabfibbdi.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/8/2015 8:00:00 AM

Valid to:
1/28/2016 7:59:59 AM

Subject:
CN=Trusted Download TYY, O=Trusted Download TYY, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6407A6EB6DAF1BC03BF0E1305112C061

File PE Metadata
Compilation timestamp:
2/8/2015 7:12:29 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7GJgF75s/F6LhC4vkHtfXTPfWdO24IV3BUwXSHpt:qJgF75s/0Lw4vkHtfTPfaO24IxbSJt

Entry address:
0x85505

Entry point:
E8, F0, AC, 00, 00, E9, 89, FE, FF, FF, CC, 8B, FF, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 8B, 73, 08, 33, 35, 40, FA, 4B, 00, 57, 8B, 06, C6, 45, FF, 00, C7, 45, F4, 01, 00, 00, 00, 8D, 7B, 10, 83, F8, FE, 74, 0D, 8B, 4E, 04, 03, CF, 33, 0C, 38, E8, 4C, A4, FF, FF, 8B, 4E, 0C, 8B, 46, 08, 03, CF, 33, 0C, 38, E8, 3C, A4, FF, FF, 8B, 45, 08, F6, 40, 04, 66, 0F, 85, 19, 01, 00, 00, 8B, 4D, 10, 8D, 55, E8, 89, 53, FC, 8B, 5B, 0C, 89, 45, E8, 89, 4D, EC, 83, FB, FE, 74, 5F, 8D, 49, 00, 8D, 04, 5B, 8B, 4C...
 
[+]

Entropy:
6.6093

Code size:
636 KB (651,264 bytes)

Remove cbacabfibbdi.exe - Powered by Reason Core Security