videoplayer-setup.exe

File

otOPia sofT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application videoplayer-setup.exe by otOPia sofT has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get1.0112online.info.
Publisher:
otOPia sofT  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
2d5929b9300b2d3036fc6533fe62003b

SHA-1:
8a8dc97676fc4323ed5488e2c6da24a8bf05f299

SHA-256:
951cca159385428b1f815f545c1547f275b66726a55d62b9eda8aa9f121ec36d

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/13/2025 5:33:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BA
5739642

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

AVG
Downloader
2016.0.3127

Bitdefender
Application.Bundler.Outbrowse.BA
1.0.20.585

Dr.Web
infected with Trojan.OutBrowse.424
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BA
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

F-Secure
Application.Bundler.Outbrowse
11.2015-27-04_2

G Data
Application.Bundler.Outbrowse.BA
15.4.25

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Application.Bundler.Outbrowse.BA
16.0.0.351

NANO AntiVirus
Trojan.Win32.OutBrowse.dqyzrr
0.30.20.1219

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Reason Heuristics
Threat.Outbrowse.Bundler
15.4.27.4

Sophos
Generic PUA HE
4.98

Trend Micro House Call
Suspici.1B63843A
7.2.117

VIPRE Antivirus
Threat.5085447
39486

File size:
1 MB (1,091,440 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Apr26-183312-9d4d23ac-f8bf-4973-a923-faca3de79ae7.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\videoplayer-setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/20/2015 4:00:00 PM

Valid to:
12/17/2015 2:59:59 PM

Subject:
CN=otOPia sofT, O=otOPia sofT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1142FA82A541A3B7A75B6FC6B8E30A93

File PE Metadata
Compilation timestamp:
4/26/2015 10:33:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:XbSaE4mvt/HXbSfc0pzupXoLtdKkcuVS3r4Ro:XbSv4mvtrIKhk23r4Ro

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5420

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file videoplayer-setup.exe has been seen being distributed by the following URL.

Remove videoplayer-setup.exe - Powered by Reason Core Security