{"id":4027,"date":"2015-01-21T19:56:08","date_gmt":"2015-01-21T19:56:08","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=4027"},"modified":"2018-05-29T12:01:02","modified_gmt":"2018-05-29T12:01:02","slug":"mari-mara-20-detection-rate-pup-optional-maru-outbrowse-revenyou","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/mari-mara-20-detection-rate-pup-optional-maru-outbrowse-revenyou\/","title":{"rendered":"Mari Mara &#8211; 20% Detection Rate &#8211; PUP.Optional.Maru \/ OutBrowse Revenyou"},"content":{"rendered":"<p>Hello! Just wanted to let you know about a publisher called <strong>Mari Mara<\/strong>\u00a0that I found earlier today. Here&#8217;s how the UAC dialog looks like when running the file:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-4029\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-publisher.png\" alt=\"Mari Mara publisher\" width=\"499\" height=\"299\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-publisher.png 499w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-publisher-300x179.png 300w\" sizes=\"(max-width: 499px) 100vw, 499px\" \/><\/a><\/p>\n<p>You can also check the digital signature under the file&#8217;s properties. According to the certificate we can see that Mari Mara appears to be located in Dublin, Ireland and that the certificate is issued by GlobalSign CodeSigning CA &#8211; G2.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-4028\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-certificate.png\" alt=\"Mari Mara certificate\" width=\"501\" height=\"520\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-certificate.png 501w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-certificate-289x300.png 289w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/a><\/p>\n<p>The <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a> report shows that the Mari Mara file should probably be avoided, since setup.exe is detected as <strong>Win-PUP\/OutBrowse<\/strong> by AhnLab-V3, <strong>Mari.668<\/strong> by AVG, <strong>PUA.OutBrowse<\/strong> by Ikarus, <strong>PUP.Optional.Maru<\/strong> by Malwarebytes and <strong>OutBrowse Revenyou<\/strong> by Sophos.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-virustotal.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-4030\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-virustotal.png\" alt=\"Mari Mara virustotal\" width=\"682\" height=\"429\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-virustotal.png 682w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/01\/Mari-Mara-virustotal-300x188.png 300w\" sizes=\"(max-width: 682px) 100vw, 682px\" \/><\/a><\/p>\n<p>Did you also find a Mari Mara file? What kind of download was it? If you remember the download link, please post it in the comments below.<\/p>\n<p>Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hello! Just wanted to let you know about a publisher called Mari Mara\u00a0that I found earlier today. Here&#8217;s how the UAC dialog looks like when running the file: You can also check the digital signature under the file&#8217;s properties. According to the certificate we can see that Mari Mara appears to be located in Dublin, &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/mari-mara-20-detection-rate-pup-optional-maru-outbrowse-revenyou\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Mari Mara &#8211; 20% Detection Rate &#8211; PUP.Optional.Maru \/ OutBrowse Revenyou<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[370,369,172],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4027"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=4027"}],"version-history":[{"count":1,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4027\/revisions"}],"predecessor-version":[{"id":4031,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/4027\/revisions\/4031"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=4027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=4027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=4027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}