bearsharesetup-r1120-w-bc.exe

BearShare

MusicLab LLC

The application bearsharesetup-r1120-w-bc.exe, “BearShare Install” by MusicLab has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from download.cdn.bearshare.com and multiple other hosts. While running, it connects to the Internet address host11-53-static.199-31-b.business.telecomitalia.it on port 80 using the HTTP protocol.
Publisher:
Musiclab, LLC  (signed by MusicLab LLC)

Product:
BearShare

Description:
BearShare Install

Version:
11.0.0.133554

MD5:
eb0226bb2403b4f9a430230f5cbfa7f7

SHA-1:
c59a0f9b108bceffa575ab5213c01f017a4e1db8

SHA-256:
e4c732cfa9804f6a812179f95e0b594c28b30840527f3d016bbe68f78b5badc3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 8:40:55 AM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.MusicToolbar.A
v2013.11.25.01

Reason Heuristics
PUP.Installer.MusicLab.Z
14.2.26.9

File size:
1.4 MB (1,428,160 bytes)

Product version:
11.0.0.133554

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bearsharesetup-r1120-w-bc.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/10/2013 5:00:00 PM

Valid to:
5/27/2015 4:59:59 PM

Subject:
CN=MusicLab LLC, OU=SECURE APPLICATION DEVELOPMENT, O=MusicLab LLC, L=New York, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1582F6B662FC5F71E4A759C63412F798

File PE Metadata
Compilation timestamp:
5/30/2013 1:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7CJJ3hQhkk9sEcDxArQs8OiLT0sM90SSd1ZdsPA4zlAPTneHrHaV:mJJGkkP0xA8skPtM90LsPmPD2r6V

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Code size:
29.5 KB (30,208 bytes)

The file bearsharesetup-r1120-w-bc.exe has been seen being distributed by the following 50 URLs.

http://download.cdn.bearshare.com/cdn/r/.../BearShareSetup-r329-n-bi.exe

http://i_mp3-es_bearshare-11-0-0-133554.foramuinareqy.com/crawled_soft/2/6/.../26818-672792-bearshare.exe

http://download.cdn.bearshare.com/cdn/r/.../BearShareSetup-r1116-n-bi.exe

http://www.megadlcenter.com/SUyTbVFPDWwqPef_qrPj2VPkB__Tv26NZy lptzoVSO7jkwhuNLFP8W5jFqk_LIZfj9hN5ldg1GJwjGOzvgxqNvOoRq90E6dUIstLMfPv8 foM0CMpckcIFiyct00n23WzS fRVvT2WWQ8Iwo8hrkpksGsLt9hVx8uRoWIW94UeyFh3rkwGdL6kcbgeAhyH2O0bcMUTA-G0AAAAT Z4fWBw80oOBtYbVuO8c4HdRvmp9kGzyGz7sSfLTGnUZRDe8tVsJRQS1aVk6ucR_ca MD

Latest 30 of 54 download URLs

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):

Remove bearsharesetup-r1120-w-bc.exe - Powered by Reason Core Security