setup.exe

GiVe awAy SOFtware

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by GiVe awAy SOFtware has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
MCBLX  (signed by GiVe awAy SOFtware)

Product:
MCBLX

Version:
3979.151127.1429.3916

MD5:
559c3f467cbfe22c447c024aa45797bc

SHA-1:
9eb3bbcc71a5bdf95e72eaf07e72035ebd3c2de9

SHA-256:
367facbe6d6933653496ce18aa725daa03421962d5e89d409989e6b31cd10b6f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/17/2025 10:10:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.9.11.19

File size:
339.6 KB (347,704 bytes)

Product version:
3979.151127.1429.3916

Copyright:
MCBLX

Trademarks:
MCBLX

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
11/24/2015 8:00:00 AM

Valid to:
1/27/2017 7:59:59 AM

Subject:
CN=GiVe awAy SOFtware, O=GiVe awAy SOFtware, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5A3AA8A7A4EDADEEFC87F9B16F898B66

File PE Metadata
Compilation timestamp:
12/6/2009 6:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:7FJ0FePbKItFd8IZzj4QXLT1lrWmOwdP/Wi/PanG7vgIo:GeHCvQbDlOw9OyPaovo

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6810

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup.exe - Powered by Reason Core Security