dell_driver_update_utility_license_key.exe

File

appS marKet abC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application dell_driver_update_utility_license_key.exe by appS marKet abC has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.down0101life.info.
Publisher:
appS marKet abC  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
5bf047a68eae12a610a20f288ff60ac1

SHA-1:
8409626bdb2db878ed1d13c40bec9a649017615a

SHA-256:
b5bacb5dfc759fbf1b08f7d3a321ac79bed207b557c2acfcccaf4ad7caf50cf2

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 2:30:29 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.29

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
PUP-gen [PUP]
150319-0

AVG
Downloader
2016.0.3156

Dr.Web
infected with Trojan.OutBrowse.225
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/28/2015

G Data
NSIS.Application.OutBrowse.AC
15.3.25

McAfee
Adware-OutBrowse.e
5600.6812

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.28.12

Sophos
Generic PUA OP
4.98

Trend Micro House Call
Suspici.F994BFB8
7.2.87

File size:
1 MB (1,100,992 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar28-075830-743da893-cd98-4d36-a6d5-c8e5ee55e9c1.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dell_driver_update_utility_license_key.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/26/2015 5:00:00 AM

Valid to:
1/28/2016 4:59:59 AM

Subject:
CN=appS marKet abC, O=appS marKet abC, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
071709D5ED48BE5FC7460A34370E0E78

File PE Metadata
Compilation timestamp:
3/28/2015 12:58:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:DbSaE4mvt/Ay6qQwjQipGl7cTvcxRwRwJulGHF:DbSv4mvSRqE4kI7cxRruI

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5477

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file dell_driver_update_utility_license_key.exe has been seen being distributed by the following URL.

Remove dell_driver_update_utility_license_key.exe - Powered by Reason Core Security