this war of mine download.exe

BON DON JOV

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application this war of mine download.exe by BON DON JOV has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.file22desktop.com.
Publisher:
BON DON JOV  (signed and verified)

MD5:
f1ee1becab53b79a4b20a7adcbf0d4d5

SHA-1:
b940fc6897d8ed7a38264134a8d90845fc730b0c

SHA-256:
484240b52dc23fcf6eb42d3796008140e2ab2432543038c532f5daf67a542d35

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 3:18:29 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Outbrowse.Gen
7.11.201.124

AVG
Downloader
2016.0.2979

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.9.21.22

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
14.0.0.1390

Malwarebytes
PUP.Optional.OutBrowse
v2015.09.21.10

Reason Heuristics
PUP.Outbrowse.BONDONJOV.Bundler (M)
15.8.11.13

Sophos
PUA 'OutBrowse Revenyou'
59

Trend Micro House Call
Suspici.D88B743E
7.2.264

File size:
574.4 KB (588,168 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\this war of mine download.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/9/2015 2:00:00 AM

Valid to:
12/18/2015 1:59:59 AM

Subject:
CN=BON DON JOV, O=BON DON JOV, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2FA767737DADE1D60ADE8683896AD37C

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8wZOE3aqN2fKDZiBCKOTfclYj8eLla0NAH85lZ9af1Ejqvw:8wZOEKqAfKNigKOTfWYjtla0Ni85ljnD

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9672

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file this war of mine download.exe has been seen being distributed by the following URL.

Remove this war of mine download.exe - Powered by Reason Core Security