k1nui.exe

Yes Apps

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application k1nui.exe by Yes Apps has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from get.0143i.info.
Publisher:
RPZTJ  (signed by Yes Apps)

Product:
RPZTJ

Version:
4557.151114.732.6403

MD5:
92ada6647d1601eedc3fae7af4367c00

SHA-1:
147e9ae84ae2fb9fbfb47567251cced2760014fa

SHA-256:
0011f161167c3f31c02862404428ee4858fb5f82be35f33991c226c14a3bd564

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
2/25/2025 12:48:26 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.YesApps.Bundler (M)
16.2.13.16

File size:
344.3 KB (352,600 bytes)

Product version:
4557.151114.732.6403

Copyright:
RPZTJ

Trademarks:
RPZTJ

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\k1nui.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/4/2015 12:07:58 PM

Valid to:
11/20/2015 12:31:49 PM

Subject:
CN=Yes Apps, O=Yes Apps, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112142ED1247F6EEDCC3B9B4A1C7F026A070

File PE Metadata
Compilation timestamp:
12/6/2009 1:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:nFJ0B2YnNCxy+ahR+rrbVqpn+zOJlNMLOb9Ztw6OQ1Ayk:+HeDvbEB+aJleLafl1Xk

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6877

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file k1nui.exe has been seen being distributed by the following URL.

Remove k1nui.exe - Powered by Reason Core Security