dns _er by المرشد للمعلوميات.rar.exe

Tiki Taka

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application dns _er by المرشد للمعلوميات.rar.exe by Tiki Taka has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Tiki Taka  (signed and verified)

MD5:
09b9789bbd00c7c2d07c91a3cf7eb5c8

SHA-1:
5911a76e8034b1eb167d426e1fa8cca24c1d0fa4

SHA-256:
b6a47ab70299e9b23c434e5debea28f25078e0ece525733e53e1ad8deff6e617

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 9:39:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.1
656

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
OutBrowse-V [PUP]
2014.9-150419

AVG
Win.Threat.Medium
2014.0.4311

Bitdefender
Gen:Variant.Adware.Jatif.300
1.0.20.545

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AltBrowse.HY
21825

Dr.Web
Trojan.OutBrowse.51
9.0.1.0109

Emsisoft Anti-Malware
Gen:Variant.Adware.Jatif.300
8.15.04.19.06

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
4/19/2015

F-Secure
Gen:Variant.Adware.Jatif
5.13.68

G Data
Gen:Variant.Adware.Jatif.300
15.4.25

herdProtect (fuzzy)
2015.7.21.4

K7 AntiVirus
Unwanted-Program
13.202.15333

Malwarebytes
PUP.Optional.OutBrowse
v2015.04.19.06

McAfee
Program.Adware-OutBrowse.c
5600.6790

MicroWorld eScan
Gen:Variant.Adware.Jatif.300
16.0.0.327

NANO AntiVirus
Trojan.Win32.OutBrowse.dmikik
0.30.16.1110

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Reason Heuristics
Threat.Outbrowse.Bundler
15.4.19.14

Sophos
OutBrowse Revenyou
4.98

VIPRE Antivirus
Threat.4784459
39354

File size:
557.7 KB (571,104 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dns _er by ?????? ??????????.rar.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/19/2014 10:39:17 AM

Valid to:
11/20/2015 10:39:17 AM

Subject:
CN=Tiki Taka, O=Tiki Taka, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112161125AC0FF3BA8BBA2651A5050D29542

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:RExDnkPOS+UQidi4ZOFEqQ2IFslkS/PtwTZHBcdUqI1QA39P:RankGElZwEC6CjNwTZHGdOhh

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)