american-muscle.exe

OUTBROWSE

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application american-muscle.exe by OUTBROWSE has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
OUTBROWSE  (signed and verified)

MD5:
e3bc2b7da4765b917f0ed5a51722dfbe

SHA-1:
72191885ea64fd22fc28eae505533cc61e2ebbfb

SHA-256:
447660bf1a24df76a4f65c365b19fa5266131a9be26a13eacaea33f19c4d36cb

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 11:53:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.Outbrowse.N
833

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2014.10.25

Avira AntiVirus
APPL/OutBrowse.lwasp
7.11.181.44

AVG
Generic
2015.0.3311

Bitdefender
Dropped:Application.Bundler.Outbrowse.N
1.0.20.1485

Dr.Web
Adware.Downware.2081
9.0.1.0297

ESET NOD32
Win32/OutBrowse.AY
8.10617

Fortinet FortiGate
Riskware/OutBrowse
10/24/2014

F-Secure
Dropped:Application.Bundler.Outbrowse
11.2014-24-10_6

G Data
Dropped:Application.Bundler.Outbrowse
14.10.24

K7 AntiVirus
Unwanted-Program
13.185.13789

Kaspersky
not-a-virus:AdWare.Win32.OutBrowse
14.0.0.3050

Malwarebytes
PUP.Optional.OutBrowse
v2014.10.24.11

McAfee
Adware-OutBrowse.b
5600.6967

MicroWorld eScan
Dropped:Application.Bundler.Outbrowse.N
15.0.0.891

NANO AntiVirus
Trojan.Win32.OutBrowse.dgnlgr
0.28.2.62841

Reason Heuristics
PUP.OUTBROWSE.P
14.10.24.22

Sophos
Generic PUA DP
4.98

VIPRE Antivirus
OutBrowse
34224

File size:
563 KB (576,496 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\american-muscle.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/7/2014 1:00:00 AM

Valid to:
4/8/2015 12:59:59 AM

Subject:
CN=OUTBROWSE, O=OUTBROWSE, STREET=Bialik Number: 143, L=Ramat Gan, S=Israel, PostalCode=5252337, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A5F03C3A375C11FD6C1C160EE8BFF923

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:W0y4BkfCLouuDJPp3AGsxoHCYY10EZvf+2jwYgM0LJnq4Q:W0YfLrFRwGnQ0AcNMeq

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove american-muscle.exe - Powered by Reason Core Security