ceac65b627cf58504e85c8c5ae113b59.exe

SAFE Store btw

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application ceac65b627cf58504e85c8c5ae113b59.exe by SAFE Store btw has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
UWDRL  (signed by SAFE Store btw)

Product:
UWDRL

Version:
2415.15616.1349.1325

MD5:
39763a170de3f813167f472e2d4a2803

SHA-1:
15d080ce70cac4a3a49107f4cc30012d3ee92519

SHA-256:
d27dd92e90e4f48d9f0724b27b43eb0120f029fe8ce6e32c9b50a91829b40d9f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 9:53:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.SAFEStor.Bundler (M)
16.7.4.22

File size:
741 KB (758,755 bytes)

Product version:
2415.15616.1349.1325

Copyright:
UWDRL

Trademarks:
UWDRL

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\windows\temp\ceac65b627cf58504e85c8c5ae113b59.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/16/2015 3:00:00 AM

Valid to:
1/28/2016 2:59:59 AM

Subject:
CN=SAFE Store btw, O=SAFE Store btw, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
472CA227323AAC3CF3D90106389D928C

File PE Metadata
Compilation timestamp:
12/6/2009 1:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:LYuF4SL1ywnGwc7M2nn4SpUuzEQMAw4TdTKfc8vy4h:LYrSU1PQ24aFMON86

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.5879

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove ceac65b627cf58504e85c8c5ae113b59.exe - Powered by Reason Core Security