update_google_chrome.exe

The application update_google_chrome.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from www.freesoftwaren.com.
MD5:
31705c55b461508bb2cfe771e0c95f50

SHA-1:
79232b39d68bd1097034f2edc9d6b7dcfbb00128

SHA-256:
da0e3e145cb99bc9a894e9fc2e5a4393230ca67a65f95a80571275a08fd1b9c7

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/28/2024 4:10:43 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Detection.Undefined
9.0.1.05190

ESET NOD32
Win32/OutBrowse.AU potentially unwanted application
8.0.319.0

File size:
516 KB (528,375 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\update_google_chrome.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:qe34a+utkqzFSRgPfapgsoWpcHKzUs8wKIrXt/RtZAC7AFq6VdXAS7U44z99X:PbTFZfaSsoZhXQ5RthUFq6DF7/e99X

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9730

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file update_google_chrome.exe has been seen being distributed by the following URL.

Remove update_google_chrome.exe - Powered by Reason Core Security