zoo tycoon 2 ultimate collection full version - fullrip download low spec pc games ratamap dow

saFe cLiCK lOL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file zoo tycoon 2 ultimate collection full version - fullrip download low spec pc games ratamap dow by saFe cLiCK lOL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. The file has been seen being downloaded from get.down1209group.info.
Publisher:
DTWVJ  (signed by saFe cLiCK lOL)

Product:
DTWVJ

Version:
1778.15531.1384.2361

MD5:
51627b678637c8041800750d51509596

SHA-1:
01531468ea0f1d5d0949b3f66b61d776e8745691

SHA-256:
5c3e6bb4b386da9ad1b69cf5b3811f5a9b8c7c8c1033831a3624ba95ee8b6b18

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/27/2024 3:03:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse.saFecLiCKlOL.Bundler (M)
15.6.24.19

File size:
744.5 KB (762,376 bytes)

Product version:
1778.15531.1384.2361

Copyright:
DTWVJ

Trademarks:
DTWVJ

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\zoo tycoon 2 ultimate collection full version - fullrip download low spec pc games ratamap download low end pc games.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/27/2015 5:00:00 PM

Valid to:
1/27/2016 3:59:59 PM

Subject:
CN=saFe cLiCK lOL, O=saFe cLiCK lOL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1D35B931645F649089CF2B35F1F31828

File PE Metadata
Compilation timestamp:
12/5/2009 2:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:t4Ottdt7VcPstjZpIBAZwiUSFK02RP3zxwFTlSdzrIx6jNyfc8vy4hM:tFtdt7Vc+ZpoAwhSeRfz8wdzRN/86J

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9839

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file zoo tycoon 2 ultimate collection full version - fullrip download low spec pc games ratamap dow has been seen being distributed by the following URL.