vlc-2.1.6a-win32setup.exe

Setup

BEST install TLL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application vlc-2.1.6a-win32setup.exe by BEST install TLL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
BEST install TLL  (signed and verified)

Product:
Setup

Version:
1.9.3.0

MD5:
8fda0f9e942d7ed0ebd632b1df016f90

SHA-1:
a0b7b69035ec99781ae252fa6c0878723263f37a

SHA-256:
e602404985964d9729f1ebb132bebdf164a18ff62557065af3b3fb2e45eacf5d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/24/2025 11:56:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.11.11.21

File size:
1.1 MB (1,152,160 bytes)

Product version:
1.9.3.0

Copyright:
Setup

Original file name:
Ionic.Zip-2015Mar13-111348-10953cb8-1b86-4e24-bf7e-1598899823ba.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vlc-2.1.6a-win32setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/12/2015 7:00:00 AM

Valid to:
1/28/2016 6:59:59 AM

Subject:
CN=BEST install TLL, O=BEST install TLL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3221D63B917F050DED1986114C8C5C86

File PE Metadata
Compilation timestamp:
3/13/2015 6:13:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:QbSaE4mvt/ju9DAt8CpTqWnwJrO/VTpwjIB:QbSv4mvNu9DA/5qWwJrgVi

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5768

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file vlc-2.1.6a-win32setup.exe has been seen being distributed by the following URL.

http://getm.0109solutions.info/.../1426245235/1426245235?71826491049YGRsMy87ZzwxNSwyNR5iNy4sNzEzHWU8KjIzNS8lbjkoH29qbV5xWnNuXWRePE5KPSdEZGRlWCRPZF9zYWkqMiooJzVZJF51ZWBtZVpnYGVjN1JDQitJXF1oWSlKaFh4ZW4iKy0pLDBdHWVpaFxnYGVjN3JjYi0uJSotLl8nc2BtMy5qXnNtbiBlWm5uOSwfeWFuNy4dYmw5Xl5zLDU

Remove vlc-2.1.6a-win32setup.exe - Powered by Reason Core Security