vlc-2.1.6a-win32setup.exe

Setup

Safe Software Sll

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application vlc-2.1.6a-win32setup.exe by Safe Software Sll has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. With this installer, users are expecting to download the VideoLAN VLC media player but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Safe Software Sll  (signed and verified)

Product:
Setup

Version:
1.9.3.0

MD5:
116e4e5707ef653c38bf252895c1694b

SHA-1:
cbcc3f2e590cac443625bdbf5c8e41fd10bf39e6

SHA-256:
3ee8d539b410f56f673ef6304e7bd4e766004fc5fda6e3235740168656ea0917

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/24/2024 5:31:18 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.SafeSoftwareSll.Bundler (M)
16.2.29.11

File size:
1.1 MB (1,146,664 bytes)

Product version:
1.9.3.0

Copyright:
Setup

Original file name:
Ionic.Zip-2015Mar08-023626-d4833f4b-3942-4a1a-b210-0987e9108133.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\vlc-2.1.6a-win32setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/5/2015 7:00:00 AM

Valid to:
1/28/2016 6:59:59 AM

Subject:
CN=Safe Software Sll, O=Safe Software Sll, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5D86B00EE6C53705927FED8F867F6A6E

File PE Metadata
Compilation timestamp:
3/8/2015 9:36:26 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:CbSaE4mvt/gWsDXVplzbMzuzyb7LBPqrAsEdvHF3Mo3:CbSv4mveWsDXVplnMzN/BSMx

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5751

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove vlc-2.1.6a-win32setup.exe - Powered by Reason Core Security