setup.exe

BesT insTall TLl

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by BesT insTall TLl has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from getr.0120b.info.
Publisher:
YPUHY  (signed by BesT insTall TLl)

Product:
YPUHY

Version:
4222.1562.1194.8349

MD5:
e8cb84a28d5e674016c61bc0af0072cf

SHA-1:
6b44028fa5d72d2e972778dace7a231d46c8a2f4

SHA-256:
a5f06c005641fdf2e5577a23029e44d40dcb2e9d4e0ff08aa74e061b826526ea

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 1:17:31 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2016.0.3078

Dr.Web
Trojan.OutBrowse.747
9.0.1.05190

ESET NOD32
Win32/OutBrowse.CB potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
6/14/2015

K7 AntiVirus
Unwanted-Program
13.205.16237

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.06.14.03

McAfee
Program.Adware-OutBrowse.g
17.6.569.0

Quick Heal
PUA.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.14.11

Trend Micro House Call
Suspici.2DBCF6CF
7.2.165

VIPRE Antivirus
Threat.4150696
40830

File size:
660.3 KB (676,160 bytes)

Product version:
4222.1562.1194.8349

Copyright:
YPUHY

Trademarks:
YPUHY

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/31/2015 1:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=BesT insTall TLl, O=BesT insTall TLl, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6412C2E114728AB3B20AD0BC651CBE42

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:1jpoH5sGEP4VDhIavdyRXDg7B04V4ljNkFuy9fc7G3g6k0TDfc8vy4h:11oJ+4BhDFyRs7B04V4EFlfc7G3gkw86

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9581

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security