installer_utorrent_french.exe

Download Manager

SAFe store btw

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application installer_utorrent_french.exe by SAFe store btw has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from mukob97f7jutiwu.kayurosireuf.info.
Publisher:
SAFe store btw  (signed and verified)

Product:
Download Manager

Version:
1.1552.134.0

MD5:
a19b62c13737ee994b03da25cbc79ac4

SHA-1:
8c8a2e34c4f6d2c0a0dcd90918df47e396f6171f

SHA-256:
d1013c1d81f0e4116c9d7c39f0225df55c1f50be4bcd994419666cec420115ac

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 12:36:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BI
552

avast!
OutBrowse-JW [PUP]
2014.9-150503

AVG
Potentially harmful program Downloader
2016.0.3121

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.OutBrowse.461
9.0.1.0123

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BI
8.15.08.01.05

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
5/3/2015

K7 AntiVirus
Unwanted-Program
13.204.16051

Malwarebytes
PUP.Optional.OutBrowse
v2015.08.01.05

McAfee
RDN/Generic.dx!drb
5600.6777

MicroWorld eScan
Application.Bundler.Outbrowse.BI
16.0.0.639

NANO AntiVirus
Trojan.Win32.OutBrowse.dqewmc
0.30.24.1357

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
DownloadManager.Bundler.Outbrowse
15.5.3.7

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
Suspici.EB1B104E
7.2.123

VIPRE Antivirus
Threat.4150696
40552

File size:
578.3 KB (592,160 bytes)

Product version:
1.1552.134.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_utorrent_french.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/8/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=SAFe store btw, O=SAFe store btw, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
320771129CDF5E84E404CA0FEC102EE3

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:vEHjNlgguxt4Vk1woboiGjvollHFod6QTjMX+AJdgb:vEY4VkSRjvKHCd6eoK

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9433

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_utorrent_french.exe has been seen being distributed by the following URL.

Remove installer_utorrent_french.exe - Powered by Reason Core Security