download kamus inggris-indonesia offline untuk pc.exe

OTOpiA SofT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application download kamus inggris-indonesia offline untuk pc.exe by OTOpiA SofT has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The file has been seen being downloaded from get.0134j.info.
Publisher:
ZXQWY  (signed by OTOpiA SofT)

Product:
ZXQWY

Version:
405.1569.838.4513

MD5:
cc12f2163638f0f5cc0c8e0bb5dd9125

SHA-1:
5f33dc7dd03d2b651c049b0c8451700ec89bb8c0

SHA-256:
e595f25a28cb9a264f07791c772ea0c5c7a5243f5c5e505ba5d4f3945818e6e8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/18/2025 7:05:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.OTOpiASo.Bundler (M)
16.4.20.9

File size:
751 KB (768,984 bytes)

Product version:
405.1569.838.4513

Copyright:
ZXQWY

Trademarks:
ZXQWY

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\download kamus inggris-indonesia offline untuk pc.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/8/2015 7:00:00 AM

Valid to:
12/18/2015 6:59:59 AM

Subject:
CN=OTOpiA SofT, O=OTOpiA SofT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
59F3BA8BC373971A5F3CE499080892F6

File PE Metadata
Compilation timestamp:
12/6/2009 5:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:lJ2xl9gEwUAcNgIfA+u5tyf0WHHFKz/8be68ZGa2GsedlJJDZecjfc8vy4hx:lJAl9g6gIfbNffHeEJDGs4lrFhQ86C

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9850

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file download kamus inggris-indonesia offline untuk pc.exe has been seen being distributed by the following URL.