autocadbook.rar_10924_i30055532_il345.exe

Runner Utility

BERSHNET LLC

The application autocadbook.rar_10924_i30055532_il345.exe by BERSHNET has been detected as adware by 23 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.186

MD5:
cda6d85789f8cb4a18c0ec49cf9771d4

SHA-1:
45de2cef6691329e454a61488d8d39dca63e5519

SHA-256:
ddddc7ad05526392a572f778dae2c0dfb7010adcaf3e7ec122932b2d5f8c5609

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
4/26/2024 12:31:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Mikey.8247
524

AhnLab V3 Security
PUP/Win32.Amonetize
2015.04.10

AVG
Generic
2016.0.3002

Bitdefender
Gen:Variant.Adware.Mikey.8247
1.0.20.1210

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.LoadMoney.IARS
21713

Dr.Web
Trojan.Amonetize
9.0.1.0242

Emsisoft Anti-Malware
Gen:Variant.Adware.Mikey.8247
8.15.08.30.12

ESET NOD32
Win32/Amonetize.DT potentially unwanted (variant)
9.11453

Fortinet FortiGate
Riskware/Agent
8/30/2015

F-Prot
W32/S-6b7bd906
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Mikey
11.2015-30-08_1

G Data
Gen:Variant.Adware.Mikey.8247
15.8.25

K7 AntiVirus
Unwanted-Program
13.202.15549

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1505

Malwarebytes
PUP.Optional.Amonetize.A
v2015.08.30.12

McAfee
Artemis!CDA6D85789F8
5600.6658

MicroWorld eScan
Gen:Variant.Adware.Mikey.8247
16.0.0.726

Panda Antivirus
Trj/Genetic.gen
15.08.30.12

Qihoo 360 Security
Win32/Virus.Downloader.736
1.0.0.1015

Reason Heuristics
PUP.Amonitize.BERSHNET (M)
15.8.30.0

Sophos
Generic PUA EF
4.98

VIPRE Antivirus
Amonetize
39214

File size:
1.1 MB (1,118,736 bytes)

Product version:
1.0.0.186

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\autocadbook.rar_10924_i30055532_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2015 2:00:00 AM

Valid to:
2/7/2016 1:59:59 AM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
2/8/2015 12:43:05 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:miN2WIJpLDrZqhRItKDjGqnS0P3I9CoMM0jvC/ekEH+jCSy5eFf:miN2FHDrmI8jGAdPY9n0jsB0/S5B

Entry address:
0x13F365

Entry point:
60, 60, E9, AE, 52, 00, 00, 83, FB, 02, E8, 63, 46, 00, 00, 00, 00, 4C, 6F, 63, 61, 6C, 41, 6C, 6C, 6F, 63, 00, BB, A1, B8, 0F, 28, D0, 7F, CD, 21, 45, 48, 1A, 5A, 04, CF, 3E, 54, 09, C5, 44, 79, 24, 2D, 36, 4D, F4, 76, F0, 98, D1, 05, 9C, C9, 96, 87, B2, 66, 84, B5, A4, E4, 8A, 19, 46, 5E, 43, E2, 3A, A3, 85, 66, 51, EC, BB, F2, F8, 1C, F0, 1F, A0, 69, AF, 36, E7, 7A, FF, 46, DC, C0, 61, 9B, 53, EB, E8, 43, 95, 51, FA, 77, 39, E0, 7A, 3D, 8C, 55, E2, 7B, E3, D1, BF, 41, 9F, E0, 0F, 58, 4F, 89, E5, A4, EC...
 
[+]

Entropy:
7.9894  (probably packed)

Code size:
99 KB (101,376 bytes)

Remove autocadbook.rar_10924_i30055532_il345.exe - Powered by Reason Core Security