setup.exe

TruStEd APps ddd

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by TruStEd APps ddd has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The file has been seen being downloaded from get.down1209group.info.
Publisher:
OKAMK  (signed by TruStEd APps ddd)

Product:
OKAMK

Version:
1871.1563.1330.8925

MD5:
b2a3e0db417ccafcae27ace1e1450813

SHA-1:
e453fef2a059ac9b9ef37363dbba97632afd7ddc

SHA-256:
bdc96f4c8df8ed211939721c8aff2ac929a11cbdb3ebdcc002355be3a6da41e7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 4:06:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.9.23.16

File size:
662 KB (677,920 bytes)

Product version:
1871.1563.1330.8925

Copyright:
OKAMK

Trademarks:
OKAMK

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/30/2015 6:00:00 PM

Valid to:
1/27/2016 4:59:59 PM

Subject:
CN=TruStEd APps ddd, O=TruStEd APps ddd, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6891BBDBFE8F2179833832F030C81515

File PE Metadata
Compilation timestamp:
12/5/2009 3:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:K0V5lWh5jj7Lbg/Jn/PBBTXdmex3X6/Q6/lKVH62OJF/1vefc8vy4h:1bYbg/JnRhX4e3XIt/6EP786

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9554

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

http://get.down1209group.info/1433294520/1433294520/.../JEwrRUttaUssTmRtQWJRRC1MXy9Vaz5SamZMSUBXYU1IaUtqR0xFSWs P2deS1F1elRHM2RrTyRTcC9MX093S0N4WmJkd3JLPUpcZHJCSWhQek5ANUEuUmRgKkttbG9WO3BOKGFOUTNLRHJRZ1IkTmlwOXNUR0k9T1prPj93Y3EyU0Rzb3JAMmVObkpPTFNCO2M2LUlCbUVOU21uSy45N1JASTBIQUQtM3NDO3UmaUItTjpdaDAwQi1LTGplTFRSVWdNaHR1Q3BqZFdmQkhcT2JgS15IWElmTC1zRjksQmFZTTM1KUVGbj1ccU5Fb0M7QmFbPXBnZHI7RmEwX2BDWVNqVFtrRUJ0TkY6QFI0bVMqamwpcx5nY29oOyovJHFiaDsw

Remove setup.exe - Powered by Reason Core Security