file installer.exe

Mari Mara

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application file installer.exe by Mari Mara has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
Mari Mara  (signed and verified)

MD5:
a091607e452c80f7a0faba40f46e2347

SHA-1:
fc527d194fb2e7da9984095e57eed413940f83c1

SHA-256:
b0e4bf34531f7b47c7cf2b28165c13d23fe1fe01d8ed530b7d08a0607ea4008e

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 12:05:05 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
MemScan:Application.Bundler.Outbrowse.Q
5805142

AhnLab V3 Security
PUP/Win32.OutBrowse
2014.11.20

Avira AntiVirus
APPL/Downloader.Gen
7.11.187.70

AVG
Potentially harmful program Downloader.CES
2014.0.4189

Bitdefender
MemScan:Application.Bundler.Outbrowse.Q
1.0.20.1615

Dr.Web
Trojan.OutBrowse.14
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BG (variant)
8.10748

Fortinet FortiGate
Riskware/OutBrowse
11/19/2014

F-Secure
MemScan:Application.Bundler.Outbrowse
11.2014-19-11_4

G Data
MemScan:Application.Bundler.Outbrowse
14.11.24

K7 AntiVirus
Unwanted-Program
13.185.14071

Malwarebytes
PUP.Optional.Maru
v2014.11.19.09

McAfee
Adware-OutBrowse.c
5600.6942

MicroWorld eScan
MemScan:Application.Bundler.Outbrowse.Q
15.0.0.969

Reason Heuristics
PUP.MariMara.O
14.11.20.9

Trend Micro House Call
Suspici.173023CD
7.2.323

VIPRE Antivirus
Threat.4150696
34232

File size:
572 KB (585,768 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\file installer.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/11/2014 11:10:16 AM

Valid to:
11/12/2015 11:10:16 AM

Subject:
CN=Mari Mara, O=Mari Mara, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112167C220B9C5568C1F2BDF4D04BEE1E24C

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:zfNoAgl/ehsHDnnoQyEnTKBvalmj39ctVR+X3:zU/jyGT0ljNqV6

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9772

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove file installer.exe - Powered by Reason Core Security