setup.exe

File

DIrect downLoAD gTT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by DIrect downLoAD gTT has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from getr.0116e.info.
Publisher:
DIrect downLoAD gTT  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
6302d2c25e22f655d35582453f526ac0

SHA-1:
203d387a296e8b3a67dedda36502bd09c1b3d2e6

SHA-256:
582688a3da7ec46b1e632412e00404efff14f69b2c307c4a66a1ffe8cf5cca3c

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 1:27:15 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BE
5687364

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.06.07

Avira AntiVirus
PUA/Outbrowse.Gen
8.3.1.6

Arcabit
Application.Bundler.Outbrowse.BE
1.0.0.425

AVG
Potentially harmful program Downloader.GIC
2014.0.4311

Bitdefender
Application.Bundler.Outbrowse.BE
1.0.20.785

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.OutBrowse.630
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BE
10.0.0.5366

ESET NOD32
Win32/OutBrowse.CB potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Bundler.Outbrowse
5.14.151

G Data
Application.Bundler.Outbrowse.BE
15.6.25

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.9.5.0

McAfee
Adware-OutBrowse.g
5600.6742

MicroWorld eScan
Application.Bundler.Outbrowse.BE
16.0.0.471

NANO AntiVirus
Trojan.Win32.OutBrowse.drthpz
0.30.24.1636

Norman
Application.Bundler.Outbrowse.BE
02.06.2015 14:23:46

Quick Heal
PUA.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.6.23

SUPERAntiSpyware
Adware.OutBrowse/Variant
9829

Trend Micro House Call
Suspici.A885EC74
7.2.157

VIPRE Antivirus
Threat.4150696
40786

File size:
1.1 MB (1,124,560 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015May14-153631-6e42d903-f699-4382-b052-1c9d11b5ac05.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/11/2015 3:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=DIrect downLoAD gTT, O=DIrect downLoAD gTT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
32873010301397F02DFA0BC253BCF5A8

File PE Metadata
Compilation timestamp:
5/14/2015 6:36:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:abSaE4mvt/t0KOAubdCKRzwOy93J/Dr9KWM27Ca++:abSv4mvL0K9uRCKRzS/rr95Cp+

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5621

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security