java.exe

safe InStAll OPT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application java.exe by safe InStAll OPT has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The installer is marketed through download protals and search ads as the free Oracle Java Runtime but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
LQEJN  (signed by safe InStAll OPT)

Product:
LQEJN

Version:
2068.15910.1369.1711

MD5:
420b325164ce7faacaa137d6bfd5fd41

SHA-1:
57ef6941489cfd8bca6f5bdb932242905327557e

SHA-256:
03ce365149a7c327297daacfec8329237b0c2db7f5b985bb1c018b745beac996

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/24/2024 1:56:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.10.18.12

File size:
547.3 KB (560,440 bytes)

Product version:
2068.15910.1369.1711

Copyright:
LQEJN

Trademarks:
LQEJN

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\java.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/30/2015 5:30:00 AM

Valid to:
1/28/2016 5:29:59 AM

Subject:
CN=safe InStAll OPT, O=safe InStAll OPT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
695B543CAB5F09BA48EDE742F7236A3F

File PE Metadata
Compilation timestamp:
12/6/2009 4:22:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:opiDvTrnZxtcZIQEF80QvlZc3U7RDFmiZbu9ix:o0rZcmQESVvlZckNFPoI

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8454

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file java.exe has been seen being distributed by the following URL.

http://get.blue9876.info/1441856775/.../1441856775?84591605586X2FvLTc5cDgtKDMwMyFbPCw1LTExIGQ5LSszLTAhaTUrHmxtZmNvY29pWWddOUVYdVsmYWRkX2ZdaFw8RGFxXB5dZGVeYmhePUhaKTEwLTItMC8wNCteXVwzXVo2KjAsLywrMDExLjExJl8sNSsrImRabmg9LiseampoOCglXW9pOCk

Remove java.exe - Powered by Reason Core Security