setup.exe

StArt playinG

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by StArt playinG has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.fluff1208.info.
Publisher:
GUTIX  (signed by StArt playinG)

Product:
GUTIX

Version:
9242.15612.801.8508

MD5:
ca98f66732c825fcefb252b1cecd2185

SHA-1:
3293f56a7b9d2dc1f0a1d986874c1ff0aec2b500

SHA-256:
6751aa0a45a6e650fd97ffd2622ef326ec38be15567e4314766b54f6686ac78e

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/1/2024 8:41:29 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2016.0.3080

ESET NOD32
Win32/OutBrowse.CB potentially unwanted (variant)
9.11777

K7 AntiVirus
Unwanted-Program
13.205.16231

McAfee
Program.Adware-OutBrowse.g
17.6.569.0

Quick Heal
PUA.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.12.17

File size:
727.8 KB (745,312 bytes)

Product version:
9242.15612.801.8508

Copyright:
GUTIX

Trademarks:
GUTIX

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/11/2015 2:00:00 AM

Valid to:
12/12/2015 12:59:59 AM

Subject:
CN=StArt playinG, O=StArt playinG, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0D7DCF7125106F9259746AE84F8487C7

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:wpBSOZvDNOyK7WSmjBQMTCoJ/QHT/OGEcdiiu1PyaxQXseH2eztSLJXoBJigsfc5:wpBVZuqtQMTN5A/2ckDmXjNkL2igB86t

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security