hack extreme installer.exe

The application hack extreme installer.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from download963.mediafire.com and multiple other hosts.
MD5:
d13ca1b0f1d558057d428c1c1cfe92e9

SHA-1:
130eb90281187c6a46cbf9f354bb63f0b53cb524

SHA-256:
273bfe3760ffa473a140f39baaa91203fdbc24aa6cded8a306b48b20d94fa142

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/19/2024 12:51:45 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.158.168

avast!
Win32:Adware-gen [Adw]
2014.9-140731

Baidu Antivirus
Adware.Win32.OutBrowse
4.0.3.14731

Dr.Web
Adware.Downware.5530
9.0.1.0212

ESET NOD32
Win32/OutBrowse
8.10052

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.181.12819

Malwarebytes
PUP.Optional.OutBrowse
v2014.07.31.06

McAfee
Artemis!D13CA1B0F1D5
5600.7052

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Trend Micro House Call
Suspicious_GEN.F47V0704
7.2.212

File size:
976.3 KB (999,699 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hack extreme installer.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:++Zn113GiwllQiK1UBEZF7NWxwntNOpdZTR:bv12LlMUBENWxwntwp/TR

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9240

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file hack extreme installer.exe has been seen being distributed by the following 2 URLs.

Remove hack extreme installer.exe - Powered by Reason Core Security