TiKi TaKa - 28% Detection Rate *

Did you just stumble upon a download or a file on your computer that has been digitally signed by TiKi TaKa? Some of the security products refers to the detected files as PUP/Win32.OutBrowse and Gen:Variant.Application.Bundler.Outbrowse.5. The detection rate for the TiKi TaKa files collected here is 28%. Please read on for more details.

You will typically see TiKi TaKa when clicking to run the file. The publisher name is displayed as the "Verified publisher" in the UAC dialog as the screencap shows:

Screenshot where TiKi TaKa appears as the verified publisher in the UAC dialog

You can also view the TiKi TaKa certificate with the following procedure:

  1. Open Windows Explorer and locate the TiKi TaKa file
  2. Right-click the file and select Properties
  3. Click on the Digital Signatures tab
  4. Click the View Certificate button

Here's a screenshot of a file digitally signed by TiKi TaKa:

Screenshot of the TiKi TaKa certificate

As you can see in the screengrab above, Windows reports that "This digital signature is OK". This means that the file has been published by TiKi TaKa and that no one has tampered with the file.

If you click the View Certificate button shown in the screenshot above, you can view all the details of the certificate, such as when it was issued, who issued the certificate, how long it is valid, and so on. You can also examine the address for TiKi TaKa, such as the street name, city and country.

thawte SHA256 Code Signing CA and GlobalSign CodeSigning CA - SHA256 - G2 has issued the TiKi TaKa certificates. You can also view the details of the issuer by clicking the View Certificate button shown in the screenshot above.

TiKi TaKa Files

These are the TiKi TaKa files I have gathered, thanks to the FreeFixer users.

Detection RatioFile Name
11/48bcecabfdhbdi.exe
14/57Player.exe
24/57dcccabfcdbfg.exe
12/57setup[1].exe

Scanner and Detection Names

Here's the detection names for the TiKi TaKa files. I have grouped the detection names by each scanner engine. Thanks to VirusTotal for the scan results.

ScannerDetection Names
AVGGeneric.A85, Downloader.EMV
AVwareTrojan.Win32.Generic!BT
Ad-AwareGen:Variant.Application.Bundler.Outbrowse.5
AgnitumPUA.OutBrowse!
AhnLab-V3PUP/Win32.OutBrowse
Antiy-AVLTrojan/Win32.TSGeneric, GrayWare[AdWare:not-a-virus]/Win32.OutBrowse
AvastWin32:OutBrowse-BU [PUP], Win32:OutBrowse-HW [PUP]
AviraPUA/Outbrowse.Gen
Baidu-InternationalPUA.Win32.OutBrowse.BBA, PUA.Win32.OutBrowse.Tikt
BitDefenderGen:Variant.Application.Bundler.Outbrowse.5
CAT-QuickHealAdware.NSIS.OutBrowse.A
ComodoApplication.Win32.AltBrowse.HY
DrWebTrojan.OutBrowse.68
ESET-NOD32a variant of Win32/OutBrowse.BA, Win32/OutBrowse.BU potentially unwanted, Win32/OutBrowse.BA potentially unwanted
F-SecureGen:Variant.Application.Bundler
FortinetRiskware/OutBrowse, Adware/OutBrowse
GDataNSIS.Application.OutBrowse.AC, Gen:Variant.Application.Bundler.Outbrowse.5
JiangminAdWare/OutBrowse.r
Kasperskynot-a-virus:Downloader.NSIS.OutBrowse.cg, not-a-virus:AdWare.Win32.OutBrowse.bxs
MalwarebytesPUP.Optional.OutBrowse
McAfeeArtemis!8225BC295461, Adware-OutBrowse.e, GenericR-DEU!68AE7DE35D15
McAfee-GW-EditionArtemis, Adware-OutBrowse.e, Artemis!PUP
MicroWorld-eScanGen:Variant.Application.Bundler.Outbrowse.5
NANO-AntivirusTrojan.Win32.KillFiles.dmtzdt, Trojan.Win32.Generic.dorbni
PandaGeneric Suspicious
SophosGeneric PUA DB, OutBrowse Revenyou
SymantecPUA.Downloader
TencentWin32.Adware.Outbrowse.Wqnm
TrendMicro-HouseCallSuspici.194156A6, TROJ_GEN.R0C1H07CJ15
VIPRETrojan.Win32.Generic!BT
ZillyaAdware.OutBrowse.Win32.13731

* How the Detection Percentage is Calculated

The detection percentage is based on that I've collected 219 scan reports for the TiKi TaKa files. 61 of these scan results came up with some sort of detection. If you like, you can view the full details of the scan results by examining the files listed above.

Analysis Details

In the analysis on this page I grouped all certificates where the signer name is set to upper and lower case variants of TiKi TaKa. These are the signer names:

The analysis is based on certificates with the following serial numbers:

Comments

No comments posted yet.

Leave a reply