tourboy-3.3.1-setup.exe

Classification: Malicious

tourboy-3.3.1-setup.exe is a malicious file sample. Linked to Bundlore malware. Reported by 1 threat source, last seen 2018-03-07.

Detection summary

  • 42 antivirus detections (62% detection ratio)
  • 0 IDS alerts
  • 0 processes observed
  • 3 contacted hosts
  • 3 DNS requests

MITRE ATT&CK associations

Malware families: BUNDLORE (S0482)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
bundlore Maltiverse 2018-03-07 09:47:04 2018-03-07 09:47:04 S0482 Bundlore

Tags

bundlore

Sample information

Filenames
tourboy-3.3.1-setup.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
560856 bytes
MD5
9d398237edb70a8ac1f5922210951b4a
SHA-1
21efc97c20f435173f609ea0f2d4752d7f190b1a
SHA-256
c3f2711d057e2aa7e2f57e7e56742c72483a99f708e3b34d7617c07082a4711a
SHA-512
c12883143a3b7f944c2f0c40fa92bf569e4da74331c6054abcf643ea03e79fea7c3c88a4d7a748ba17540ea5acae662839c8931645635801f7709f2b31770165
First indexed
2018-03-07 09:47:04
Last updated
2026-04-15 01:02:20

Antivirus detections

EngineDetection
AVGWin32:Malware-gen
AVwareTrojan.Win32.Generic!BT
Ad-AwareGen:Variant.Application.Bundler.DownloadGuide.48
AhnLab-V3PUP/Win32.Generic.C1118821
ArcabitTrojan.Application.Bundler.DownloadGuide.48
AvastWin32:Malware-gen
BitDefenderGen:Variant.Application.Bundler.DownloadGuide.48
CAT-QuickHealPUA.Freemiumgm2.Gen
CrowdStrikemalicious_confidence_100% (D)
CyrenW32/S-58b25de1!Eldorado
DrWebTrojan.Siggen7.35808
ESET-NOD32a variant of Win32/DownloadGuide.D potentially unwanted
EmsisoftGen:Variant.Application.Bundler.DownloadGuide.48 (B)
Endgamemalicious (high confidence)
F-ProtW32/S-58b25de1!Eldorado
FortinetRiskware/DownloaderGuide
GDataWin32.Application.DownloadGuide.T
IkarusPUA.DownloadGuide
Invinceaheuristic
K7AntiVirusAdware ( 004b92681 )
K7GWAdware ( 004b92681 )
Kasperskynot-a-virus:HEUR:Downloader.Win32.DownloaderGuide.gen
MAXmalware (ai score=99)
MalwarebytesAdware.Downloader
McAfeePUP-FXK
McAfee-GW-EditionBehavesLike.Win32.Downloader.hh
MicroWorld-eScanGen:Variant.Application.Bundler.DownloadGuide.48
MicrosoftPUA:Win32/DownloadGuide
NANO-AntivirusTrojan.Win32.Covus.eyaiki
Qihoo-360Win32/Application.a1c
SentinelOnestatic engine - malicious
SymantecPUA.Downloader
TrendMicroPUA_DownloadGuide.SM
TrendMicro-HouseCallPUA_DownloadGuide.SM
VBA32BScope.Downloader.DownloaderGuide
VIPRETrojan.Win32.Generic!BT
ViRobotAdware.Downloadguide.560856.AMR
WebrootPua.Freemium
YandexPUA.Downloader!
ZillyaAdware.GenericKD.Win32.8298
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.DownloaderGuide.gen
eGambitUnsafe.AI_Score_99%

Network contacts

104.40.156.71 104.45.146.238 93.184.221.200

DNS requests

dlg-messages.buzzrin.de dlg-configs.buzzrin.de az687722.vo.msecnd.net