virus.exe

The application virus.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download1990.mediafire.com and multiple other hosts.
MD5:
8420a00d9bd040a206b957667077b103

SHA-1:
36a548d1344cc7cc10611f32cbfcef2ebb51d170

SHA-256:
cc0500fd4acfa0e1f7736edafef1af979ea16df09546d2c31e1b0dd659fdf789

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/27/2024 7:24:20 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Risktool.Msil.Injecter!c
2.1.4+

Agnitum Outpost
Riskware.Injecter
7.1.1

AVG
HackTool
2017.0.2813

Baidu Antivirus
Hacktool.Win32.Injector
4.0.3.1635

Comodo Security
ApplicUnsaf.Win32.DllInject.~I
24275

Dr.Web
Tool.InjDll.12
9.0.1.065

ESET NOD32
Win32/DllInject.DM potentially unsafe
10.13060

Fortinet FortiGate
Riskware/Injecter
3/5/2016

G Data
Win32.Trojan.Agent.SZ6YSK
16.3.25

IKARUS anti.virus
Trojan.Win32.Crypt
t3scan.2.0.7.0

K7 AntiVirus
Riskware
13.213.18807

Kaspersky
not-a-virus:RiskTool.MSIL.Injecter
14.0.0.561

Malwarebytes
RiskWare.Injector.DC
v2016.03.05.09

McAfee
Artemis!03E95431DDC7
5600.6469

NANO AntiVirus
Riskware.Win32.XPACK.dedmyj
1.0.14.6204

Quick Heal
RiskTool.MSIL.g3 (Not a Virus)
3.16.14.00

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.16303

Sophos
Generic PUA KB (PUA)
4.98

Trend Micro
TROJ_GE.C88B3583
10.465.05

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
47346

Zillya! Antivirus
Adware.OutBrowse.Win32.79022
2.0.0.2673

File size:
2 MB (2,084,093 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\virus.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
49152:w68rNKHmeIArkEw8WEGz2O7aobFSaC6iqhrYwD7EH:4rNKVVr7wAu2O7aoBSk/EH

Entry point:
52, 61, 72, 21, 1A, 07, 00, CF, 90, 73, 00, 00, 0D, 00, 00, 00, 00, 00, 00, 00, 30, 2E, 74, A0, 80, 48, 00, 04, 22, 00, 00, 00, 58, 00, 00, 02, EE, 04, 1E, 84, 7C, 92, 6D, 46, 1D, 33, 28, 00, 20, 00, 00, 00, 42, 6C, 6F, 63, 6B, 61, 64, 65, 20, 33, 44, 20, 68, 61, 63, 6B, 20, 62, 79, 20, 54, 77, 69, 73, 74, 20, 46, 72, 5C, 6D, 61, 6E, 61, 67, 65, 64, 2E, 64, 6C, 6C, 14, 21, 91, 51, 0C, CC, CD, 00, 14, 1E, 3B, 9E, 37, 98, 30, 66, 00, 2F, 30, 78, 9F, 21, 85, 1F, 1C, 24, 80, 10, 24, 02, 48, 05, 22, 89, 1E, 07...
 
[+]

The file virus.exe has been seen being distributed by the following 4 URLs.

http://download1990.mediafire.com/4za2hcdle7mg/.../Virus.exe

http://download1990.mediafire.com/9x26lyysyfhg/.../Virus.exe

Remove virus.exe - Powered by Reason Core Security