ebfcabfbdhbeh.exe

sAfe DoWnlOaD gtl

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application ebfcabfbdhbeh.exe by sAfe DoWnlOaD gtl has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
sAfe DoWnlOaD gtl  (signed and verified)

Version:
2015.415.120.64

MD5:
f406fd59b2eb4fb2a6528e5c4de9059b

SHA-1:
deaa182ae112d68dd62953bd189655dd229f5fab

SHA-256:
8f2fcb7e42fc9970f213d01ddbfcb2bad18fbd0733379fc717f7ca3c19375e4b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 5:21:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.sAfeDoWn (M)
16.4.2.13

File size:
764 KB (782,376 bytes)

Product version:
2015.415.120.64

Copyright:
Copyright (C) 2015

Original file name:
201541512064.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\ebfcabfbdhbeh.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/12/2015 2:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=sAfe DoWnlOaD gtl, O=sAfe DoWnlOaD gtl, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
263ED9CA1E1EB9DDF77844540EB8042F

File PE Metadata
Compilation timestamp:
4/15/2015 2:00:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:7Lob/KIiOTuJglw6zHl8awiu+tctg8lCvOHZ03hmRQYUC8QnRhitMudwUJ5Plaw:4b/KIiOTuJz6DlGiuLg8lCOZchcQZQnG

Entry address:
0x7A77B

Entry point:
E8, 4A, A9, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, E0, 57, 49, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 68, 50, 49, 00, C9, C2, 08, 00, B8, 0F, 5C, 48, 00, A3, 78, 1F, 4B, 00, C7, 05, 7C, 1F, 4B, 00, 05, 53, 48, 00, C7, 05, 80, 1F, 4B, 00, B9, 52, 48, 00, C7, 05, 84, 1F, 4B, 00, F2, 52, 48, 00, C7, 05...
 
[+]

Entropy:
6.6119

Code size:
590.5 KB (604,672 bytes)

Remove ebfcabfbdhbeh.exe - Powered by Reason Core Security