game_hack.exe

The application game_hack.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download1222.mediafire.com and multiple other hosts.
MD5:
1797e6c3e22121e1d51dc920f8466621

SHA-1:
bc218457f06762c46252a8d377021fc0f77235e5

SHA-256:
55155d130cfb7621d0a78e26f1e049fc8d34fb78876f145882982ddeb79daff0

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/5/2024 6:58:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.OutBrowse.B
984

AhnLab V3 Security
PUP/Win32.OutBrowse
14.05.26

avast!
Win32:Adware-gen [Adw]
2014.9-140526

Baidu Antivirus
Hacktool.Win32.OutBrowse
4.0.3.14526

Bitdefender
Dropped:Application.OutBrowse.B
1.0.20.730

Dr.Web
Adware.Downware.2081
9.0.1.0146

ESET NOD32
Win32/OutBrowse
8.9790

Fortinet FortiGate
Riskware/OutBrowse
5/26/2014

F-Secure
Dropped:Application.OutBrowse.B
11.2014-26-05_2

G Data
Dropped:Application.OutBrowse
14.5.24

K7 AntiVirus
Trojan
13.177.12041

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
14.0.0.3807

McAfee
Artemis!1797E6C3E221
5600.7118

MicroWorld eScan
Dropped:Application.OutBrowse.B
15.0.0.438

NANO AntiVirus
Trojan.Win32.Generic.cthmwf
0.28.0.59826

Panda Antivirus
Trj/CI.A
14.05.26.04

Sophos
Generic PUA LM
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0OE114
7.2.146

Trend Micro
TROJ_GEN.R0CBC0OE114
10.465.26

Vba32 AntiVirus
Downloader.OutBrowse
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29128

File size:
965.4 KB (988,556 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\game_hack.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:RGR7mcC0Wa3k3p8SJiJYWJipUi7vcJ3YONye1tVAwjbPQl7U:yilQkZpJiGWJipU+EGOA4tVh/PS7U

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file game_hack.exe has been seen being distributed by the following 2 URLs.

Remove game_hack.exe - Powered by Reason Core Security