15214_offer.exe

The application 15214_offer.exe has been detected as a potentially unwanted program by 19 anti-malware scanners.
MD5:
5a4d714cc3d3959edca9125645e8dc5a

SHA-1:
a3dcd59efe103270d40f73ed7cbd56d411ff2161

SHA-256:
1378ec883f0d411bb5ca6de252e6e074b5f2414b14d3a096988fd1f2290f7440

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 2:04:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.PHI
6542620

Avira AntiVirus
Adware/Gertokr.879104.1
7.11.206.68

avast!
Win32:Malware-gen
150101-1

AVG
Generic6
2016.0.3186

Baidu Antivirus
Adware.Win32.Gertokr
4.0.3.1532

Bitdefender
Adware.Agent.PHI
1.0.20.285

Comodo Security
ApplicUnwnt
20920

Dr.Web
Adware.Gertokr.1
9.0.1.05190

Emsisoft Anti-Malware
Adware.Agent.PHI
9.0.0.4799

ESET NOD32
Win32/Adware.Gertokr.B application
7.0.302.0

F-Secure
Adware.Agent.PHI
11.2015-26-02_5

G Data
Adware.Agent.PHI
15.2.25

IKARUS anti.virus
PUA.Gertokr
t3scan.1.8.6.0

MicroWorld eScan
Adware.Agent.PHI
16.0.0.171

NANO AntiVirus
Trojan.Win32.RYSJ1244.dhgboy
0.30.0.296

nProtect
Adware.Agent.PHI
15.02.26.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.2.0

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.26757
2.0.0.2083

File size:
855.7 KB (876,244 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\15214_offer.exe

File PE Metadata
Compilation timestamp:
10/14/2014 10:38:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:dh77yi4TPdhp+aKKGshjIlhPjLZOH8EAzcLLGIlP5EbUdwceDd:dd74FhsaKKBjIlZLZOHLAzcHjt5gHDd

Entry address:
0x9024A

Entry point:
E8, B1, FB, 00, 00, E9, 7F, FE, FF, FF, E8, 94, 6A, 00, 00, 85, C0, 75, 06, B8, 14, 36, 4C, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, 60, 6A, 00, 00, 85, C0, 75, 06, B8, 10, 36, 4C, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, A8, 34, 4C, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
6.6302

Code size:
687.5 KB (704,000 bytes)

Remove 15214_offer.exe - Powered by Reason Core Security