driverrevolution-setup.exe

LLC

The application driverrevolution-setup.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from nice-tower.ru.
Publisher:
LLC   (signed and verified)

Version:
2.4.5.4

MD5:
f527d307ff4590dadc069057e5cbbb7f

SHA-1:
0eff16b9d7960e3bd4d37f6f01645f9b88ff89e8

SHA-256:
a5f175f2b04ad024f5ce38982233faa19fdba1612b9c927ff4151c22012ee0c5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/27/2024 12:41:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize.Installer (M)
16.3.15.21

File size:
3.6 MB (3,748,360 bytes)

Product version:
2.4.5.4

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\driverrevolution-setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/26/2015 5:00:00 AM

Valid to:
11/26/2016 4:59:59 AM

Subject:
CN="LLC ""AYTI-FORMULA""", OU=IT, O="LLC ""AYTI-FORMULA""", STREET="vul. Tetyany Yablonskoyi, 1", L=Kiev, S=Kiev, PostalCode=03058, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0932E6421C4C1E151CA4B5DA22214D64

File PE Metadata
Compilation timestamp:
3/27/2011 12:29:22 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
49152:UN3rL03Sg02y3fgSfxDgZoId8UShjspLUKl:UFrIigry3fgEGNkhIV

Entry address:
0x1D8FB0

Entry point:
55, 8B, EC, 81, EC, C4, 01, 00, 00, 33, C0, 2B, 85, 68, FF, FF, FF, 0D, F1, 3D, 08, 00, 88, 85, EE, FE, FF, FF, C7, 45, 94, 00, 00, 00, 00, B9, 0A, 4A, 00, 00, 66, 89, 4D, DC, C7, 85, A8, FE, FF, FF, 00, 00, 00, 00, C7, 85, 18, FF, FF, FF, 8E, 4E, 09, 00, C7, 85, 1C, FF, FF, FF, 00, 00, 00, 00, 0F, B6, 95, 77, FE, FF, FF, 81, FA, 98, 11, 0D, 00, 75, 0C, 81, BD, E0, FE, FF, FF, 11, 29, 01, 00, 73, 58, C7, 85, 48, FE, FF, FF, 00, 00, 00, 00, 8B, 45, F8, 0D, 28, A4, 00, 00, 66, 89, 85, 8C, FE, FF, FF, C6, 45...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.2 MB (2,334,720 bytes)

The file driverrevolution-setup.exe has been seen being distributed by the following URL.

Remove driverrevolution-setup.exe - Powered by Reason Core Security