installer_codec_pack_dutch.exe

Tiki Taka

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application installer_codec_pack_dutch.exe by Tiki Taka has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from codecpack.mutajoreto.com.
Publisher:
Tiki Taka  (signed and verified)

MD5:
635b3269781d382f999a7f0b3e33dfb3

SHA-1:
744293649393d1db42dd361d7c0b5ee057d7b5c0

SHA-256:
ad091a302ab99fc427197741df8178bd8c77403e919f94f9fae9cc0adfcdfae9

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/25/2024 8:18:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.1
6758121

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.214.92

avast!
OutBrowse-V [PUP]
2014.9-150306

AVG
Win.Threat.Medium
2016.0.3178

Bitdefender
Gen:Variant.Application.Bundler.Outbrowse.1
1.0.20.325

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.AltBrowse.HY
21315

Dr.Web
Trojan.OutBrowse.51
9.0.1.065

Emsisoft Anti-Malware
Gen:Variant.Adware.Jatif.300
8.15.03.06.01

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/6/2015

F-Secure
Gen:Variant.Adware.Jatif
11.2015-06-03_6

G Data
Gen:Variant.Application.Bundler.Outbrowse
15.3.25

K7 AntiVirus
Unwanted-Program
13.200.15187

Malwarebytes
PUP.Optional.OutBrowse
v2015.03.06.01

McAfee
Program.Adware-OutBrowse.c
5600.6834

MicroWorld eScan
Gen:Variant.Adware.Jatif.300
16.0.0.195

NANO AntiVirus
Trojan.Win32.OutBrowse.dmikik
0.30.0.296

Quick Heal
Adware.NSIS.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.6.13

Trend Micro House Call
Suspici.0C6DACD5
7.2.65

VIPRE Antivirus
Threat.4784459
39354

File size:
557.9 KB (571,240 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_codec_pack_dutch.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/19/2014 10:39:17 AM

Valid to:
11/20/2015 10:39:17 AM

Subject:
CN=Tiki Taka, O=Tiki Taka, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112161125AC0FF3BA8BBA2651A5050D29542

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:d/xDnkPOS+UQidi4ZOFEqQ2IFslkS/PtwTZHBcdUqI1QA395:dBnkGElZwEC6CjNwTZHGdOhn

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_codec_pack_dutch.exe has been seen being distributed by the following URL.

Remove installer_codec_pack_dutch.exe - Powered by Reason Core Security