non confirmé 233527.crdownload

beST instALL TLL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file non confirmé 233527.crdownload by beST instALL TLL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
SZSQO  (signed by beST instALL TLL)

Product:
SZSQO

Version:
7190.15625.1196.8372

MD5:
25165f83023587d972be0eabb8ccd1a9

SHA-1:
69b85748ffe1433c78105a9e43b313ee7b36dc6a

SHA-256:
8bfff58c02c9f694fadf9cfe133f7ebbe2b11ae512974a4b2272c6c9e5436d7e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/24/2024 5:25:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.9.19.12

File size:
755.6 KB (773,744 bytes)

Product version:
7190.15625.1196.8372

Copyright:
SZSQO

Trademarks:
SZSQO

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\non confirmé 233527.crdownload

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/25/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=beST instALL TLL, O=beST instALL TLL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
221114DBCC1504B32397AE2D004F0458

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:p3TMeg70F7VHEzT00SX5/a45JxScoWxi8HHFnX+GsxGDkQA3R//Jfc8vy4h:pDMzaJEzJEAcop8HlX+LGAI86

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove non confirmé 233527.crdownload - Powered by Reason Core Security