uh hack v1.1.7.exe

Trusted Apps DDd

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application uh hack v1.1.7.exe by Trusted Apps DDd has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
Trusted Apps DDd  (signed and verified)

MD5:
4c169d0a929250e95787728a1f3304ad

SHA-1:
5aafc7b599fcc573bdf16e0a949af17d716d540f

SHA-256:
6412bef00aa8f201cdfe56ba5efd6345288db8688d898ffdab7abda4b6de13dd

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 10:54:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.TrustedA.Bundler (M)
16.7.3.12

File size:
598.9 KB (613,240 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Neovisno o jeziku

Common path:
C:\users\{user}\downloads\uh hack v1.1.7.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/19/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=Trusted Apps DDd, O=Trusted Apps DDd, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2A6EDA1BDEEDEEB7996DA37C61AE9E92

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:VVUIhZWDteipQ7JF+Rl9MrPD+pBMKB/bTJX2MvBUYp7b:VVUic0OQ7JF2HJH8MJFJ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove uh hack v1.1.7.exe - Powered by Reason Core Security