download windows 7 ultimate sp1 32 bit dan 64 bit and activation 100% working.exe

Setup

Safe store BTW

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application download windows 7 ultimate sp1 32 bit dan 64 bit and activation 100% working.exe by Safe store BTW has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Safe store BTW  (signed and verified)

Product:
Setup

Version:
1.9.3.0

MD5:
b6696d2591ac568f4d36308d42cac680

SHA-1:
9fc162bfc258db70611d47fb37c625fdd9e18cd2

SHA-256:
0c228b5bb1696e4114826830f63662eaa53ca56f0c0054f7f1c2e24e42136163

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 8:13:16 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.214.46

avast!
PUP-gen [PUP]
150129-1

AVG
Adware AdPlugin.CUA
2014.0.4257

Dr.Web
infected with Trojan.OutBrowse.115
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/6/2015

Malwarebytes
PUP.Optional.OutBrowse
v2015.03.06.08

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

NANO AntiVirus
Riskware.Win32.OutBrowse.dorbcs
0.30.0.296

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.18.1

Sophos
Generic PUA EP
4.98

Trend Micro House Call
TROJ_GE.58B8EAEF
7.2.65

Trend Micro
TROJ_GE.58B8EAEF
10.465.06

VIPRE Antivirus
Threat.4150696
37788

File size:
1.1 MB (1,129,536 bytes)

Product version:
1.9.3.0

Copyright:
Setup

Original file name:
Ionic.Zip-2015Feb25-182754-e02db3f8-0b2a-4f40-a5a4-e1a345f6caa0.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Common path:
C:\users\{user}\downloads\download windows 7 ultimate sp1 32 bit dan 64 bit and activation 100% working.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/19/2015 2:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=Safe store BTW, O=Safe store BTW, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
24C8104DE8CCEE31A3C805935F55EFDE

File PE Metadata
Compilation timestamp:
2/25/2015 8:27:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:jMiy4IadS4ms5I6e66fEheKh3sVrctYEmwnN/D7PBGyd/RwuJqEnpYXtLsq8xlYD:jbSaE4mvt/SCoqE/n/l/66p4YjY8U4+

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5650

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file download windows 7 ultimate sp1 32 bit dan 64 bit and activation 100% working.exe has been seen being distributed by the following URL.