evernote.exe

File

appS marKet abC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application evernote.exe by appS marKet abC has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
appS marKet abC  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
99c2f18799b54693ea928970270242c3

SHA-1:
3a2363591ef4ff783e3fa29fb9f5107fb8ae0b63

SHA-256:
0e475a0d14163ea1a9187f19d994f98856271554f919989fab143e39bee5bd33

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 3:31:23 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.31

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

Dr.Web
infected with Trojan.OutBrowse.253
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted
9.11401

G Data
NSIS.Application.OutBrowse.AC
15.3.25

Malwarebytes
PUP.Optional.Outbrowse.Gen
v2015.03.30.06

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.30.18

File size:
1 MB (1,100,664 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar29-151401-0dd3900a-1828-483e-b99e-b0b7418a8c37.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\evernote.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/25/2015 8:00:00 PM

Valid to:
1/27/2016 6:59:59 PM

Subject:
CN=appS marKet abC, O=appS marKet abC, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
071709D5ED48BE5FC7460A34370E0E78

File PE Metadata
Compilation timestamp:
3/29/2015 11:14:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:9bSaE4mvt/hxenen6rSR7EaOSxhJ6qeCW5oW:9bSv4mvzxsGren+W

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5475

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file evernote.exe has been seen being distributed by the following URL.

Remove evernote.exe - Powered by Reason Core Security