Ionic.Zip-2015May02-140352-269f95de-8fa3-4066-a953-4744d211f052.exe

File

Safe inStAll OPt

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Ionic.Zip-2015May02-140352-269f95de-8fa3-4066-a953-4744d211f052.exe by Safe inStAll OPt has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
Safe inStAll OPt  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
d35393b2026343ec16987e86b2e9dcf3

SHA-1:
8d9494f37904b7aa2ad1903cc7cbf86b6b067d74

SHA-256:
a1a8072f06aa7387c529104da953e95a1a03dac42ffa76f24f38cf329904ebc9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/6/2024 12:48:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.7.31.11

File size:
1.1 MB (1,101,960 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015May02-140352-269f95de-8fa3-4066-a953-4744d211f052.exe

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\8202.tmp

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/29/2015 7:00:00 PM

Valid to:
1/27/2016 5:59:59 PM

Subject:
CN=Safe inStAll OPt, O=Safe inStAll OPt, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
491A40F82F56114B1832E9479B780B0A

File PE Metadata
Compilation timestamp:
5/2/2015 9:03:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:HbSaE4mvt/1DWEFGo2eN9VNKxD1fyNuwoyb:HbSv4mvT6EFjg5yz7b

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5487

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)