unconfirmed 772411.torchdownload

Apps market ABC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file unconfirmed 772411.torchdownload by Apps market ABC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
Apps market ABC  (signed and verified)

MD5:
ea371ee3799f2495fa34bd9c6f7e7216

SHA-1:
bdcb0b09b3402c03d9c230989d733d537390d9b2

SHA-256:
587dcd0f3637dfb672ece873017eb4cbba299363bce4e70f422f8310a679b000

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 4:01:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.10.9.21

File size:
610.9 KB (625,552 bytes)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\unconfirmed 772411.torchdownload

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/31/2015 8:00:00 PM

Valid to:
1/27/2016 7:59:59 PM

Subject:
CN=Apps market ABC, O=Apps market ABC, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6BE197B02D2951B23855B9517380D4E8

File PE Metadata
Compilation timestamp:
12/5/2009 6:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:elW3aGSE++yo/REQZAcZq4129Ak5Koe6bDaW2kiZtEf9sSKMX5OLe5E+:elsanu/+QZAcoJR5UfH2qMX5L5B

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove unconfirmed 772411.torchdownload - Powered by Reason Core Security