windows7 loader activator.exe

Salyutem Plyus LLC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application windows7 loader activator.exe by Salyutem Plyus has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.down1211group.info and multiple other hosts.
Publisher:
Salyutem Plyus LLC  (signed and verified)

MD5:
8ba765fc203c7432b6a5636b11f7f75c

SHA-1:
76e3beb66fdbf114181d820ca173dec2923cd7c6

SHA-256:
d43d9b3601e2496c81e18656f61dd55b4f1238e79400be5669faf575e47e52c5

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 5:19:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.Outbrowse.AB
6334838

AhnLab V3 Security
PUP/Win32.OutBrowse
2014.12.31

Avira AntiVirus
APPL/Outbrowse.Gen
7.11.198.192

AVG
Potentially harmful program Downloader.CXN
2014.0.4253

Bitdefender
Dropped:Application.Bundler.Outbrowse.AB
1.0.20.1825

Dr.Web
Trojan.OutBrowse.55
9.0.1.05190

Emsisoft Anti-Malware
Dropped:Application.Bundler.Outbrowse.AB
9.0.0.4668

ESET NOD32
Win32/OutBrowse.BP potentially unwanted application
7.0.302.0

F-Secure
Riskware.Dropped:Application.Bundler.Outbrowse
5.13.68

G Data
Dropped:Application.Bundler.Outbrowse.AB
14.12.24

Malwarebytes
PUP.Optional.OutBrowse
v2014.12.31.05

MicroWorld eScan
Dropped:Application.Bundler.Outbrowse.AB
15.0.0.1095

Norman
Dropped:Application.Bundler.Outbrowse.AB
29.12.2014 07:19:03

Reason Heuristics
PUP.SalyutemPlyus.Z
15.1.4.13

Sophos
Generic PUA IJ
4.98

VIPRE Antivirus
Threat.4150696
35418

File size:
581.1 KB (595,080 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\windows7 loader activator.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
12/15/2014 1:00:00 AM

Valid to:
12/16/2015 12:59:59 AM

Subject:
CN=Salyutem Plyus LLC, O=Salyutem Plyus LLC, L=Kharkiv, S=Arkansas, C=UA

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6B6BB9E1A48F64F47503D8DCF6A5D0D3

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:eT37m5iegqX4bfguUKqy6zbSbhYkYxaGjxVO051rCBwmMGx6:eXm55Naqy6zbSqkAVOe1Q3ML

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file windows7 loader activator.exe has been seen being distributed by the following 4 URLs.

Remove windows7 loader activator.exe - Powered by Reason Core Security