setup.exe

File

MARi MarA

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by MARi MarA has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from getm.0108box.info.
Publisher:
MARi MarA  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
ecdf9a32090231b9b0e3f61345b6b9d2

SHA-1:
33d815ca01359ce49f653fa14dc20ca0c934e929

SHA-256:
8e80685346c74584e918e494067e87247cc911141211e7ce7d781a1a8f1d5917

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 2:00:18 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BE
5512208

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.05.19

AVG
Downloader
2016.0.3105

Bitdefender
Application.Bundler.Outbrowse.BE
1.0.20.690

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BE
10.0.0.5366

ESET NOD32
Win32/OutBrowse.CB potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Bundler.Outbrowse
5.13.68

G Data
Application.Bundler.Outbrowse.BE
15.5.25

McAfee
Adware-OutBrowse.g
5600.6761

MicroWorld eScan
Application.Bundler.Outbrowse.BE
16.0.0.414

Reason Heuristics
PUP.Outbrowse.Bundler
15.5.18.17

SUPERAntiSpyware
Adware.OutBrowse/Variant
9867

Trend Micro House Call
Suspici.D63490C9
7.2.138

File size:
1.2 MB (1,222,976 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015May18-104401-ab80f51f-1739-4734-aa2d-65f39445e881.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/11/2015 2:00:00 AM

Valid to:
12/18/2015 12:59:59 AM

Subject:
CN=MARi MarA, O=MARi MarA, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
433AB6E66BBBCBC24D186A9EB43A41F6

File PE Metadata
Compilation timestamp:
5/18/2015 12:44:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:8Miy4IadS4ms5I6e66fEheKhbsuHOqMcuPXUsPaXpKRqXlh+L4BvB2eQPXpItJDy:8bSaE4mvt/OXHiPXUVflvSaHDkQPMrD

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6128

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security