setup.exe

File

otOPia sofT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by otOPia sofT has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get1.0112online.info.
Publisher:
otOPia sofT  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
313a699c010fdc63aa9772260d90228d

SHA-1:
d3e3b0839be5bf5281b367db490c87292f6b398b

SHA-256:
1f6cde63cc746ee551ba4b240c08fa7072c2a2a08e2800a9d6edb497528a3c6b

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/13/2025 5:30:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BA
5727678

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.04.27

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

AVG
Downloader
2016.0.3127

Bitdefender
Application.Bundler.Outbrowse.BA
1.0.20.585

Dr.Web
infected with Trojan.OutBrowse.444
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BA
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

F-Secure
Application.Bundler.Outbrowse
11.2015-27-04_2

G Data
Application.Bundler.Outbrowse.BA
15.4.25

McAfee
Adware-OutBrowse.e
5600.6783

MicroWorld eScan
Application.Bundler.Outbrowse.BA
16.0.0.351

NANO AntiVirus
Trojan.Win32.OutBrowse.dqzhmi
0.30.20.1219

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Reason Heuristics
Threat.Outbrowse.Bundler
15.4.26.17

VIPRE Antivirus
Threat.5085447
39676

File size:
1 MB (1,099,992 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Apr26-134338-f1583b60-0c19-4037-a233-2654edb1038d.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/21/2015 1:00:00 AM

Valid to:
12/17/2015 11:59:59 PM

Subject:
CN=otOPia sofT, O=otOPia sofT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1142FA82A541A3B7A75B6FC6B8E30A93

File PE Metadata
Compilation timestamp:
4/26/2015 2:43:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:5bSaE4mvt/yr3EjCprgLmVrOfi+CjDCfZ1PT:5bSv4mvgTR2LIrOaVChBT

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5477

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security