tmp00000001f88b6f46caec05f6

TP Verytek LLC

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file tmp00000001f88b6f46caec05f6 by TP Verytek has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
TP Verytek LLC  (signed and verified)

MD5:
0b8063e7e1368e26bab9826b6bad3572

SHA-1:
b4ed29cd74e5f7d83b1095be5da6f52f0c4f7832

SHA-256:
e9901bbab463e7494528f17a834bacd71a3176a882e1b8223bf9e5e28ba92755

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 3:30:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.10.24.7

File size:
512 KB (524,288 bytes)

Common path:
C:\windows\temp\tmp00000001f88b6f46caec05f6

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
12/2/2014 7:00:00 AM

Valid to:
12/3/2015 6:59:59 AM

Subject:
CN=TP Verytek LLC, O=TP Verytek LLC, L=Kharkiv, S=Kharkiv, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5670E3D6A2BE49E371D3E95BCBB32A8A

File PE Metadata
Compilation timestamp:
9/17/2014 1:29:51 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:gMLcy63EkalaxcXHAcONFxRNEOlsmOlmTAS2Yc79T:Tcy63EkalaxcXHcNjEWs6TAS2Yc1

Entry address:
0x16DE0

Entry point:
4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 83, EC, 28, 83, 7C, 24, 38, 01, 75, 05, E8, D2, B6, 00, 00, 4C, 8B, 44, 24, 40, 8B, 54, 24, 38, 48, 8B, 4C, 24, 30, E8, 0F, 00, 00, 00, 48, 83, C4, 28, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 83, EC, 48, C7, 44, 24, 30, 01, 00, 00, 00, 83, 7C, 24, 58, 00, 75, 10, 83, 3D, 58, BF, 04, 00, 00, 75, 07, 33, C0, E9, 1F, 01, 00, 00, 83, 7C, 24, 58, 01, 74, 07, 83, 7C, 24, 58, 02, 75, 4E, 48...
 
[+]

Entropy:
5.3990

Code size:
281.5 KB (288,256 bytes)

Remove tmp00000001f88b6f46caec05f6 - Powered by Reason Core Security