bsu3y.exe

mlru

Kolac

The application bsu3y.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.inditedexplanatory.webcam.
Publisher:
Kolac

Product:
mlru

Description:
fast install

Version:
176.119.82.113

MD5:
25f5e9b07997107f887c3e72811ef114

SHA-1:
6a6ef016a9959df5d522328864ab3dfb52ef8cdd

SHA-256:
20d65584089a8be0d2a42642709acb6c47fb936d1760ee559596cab0761b1047

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/20/2024 6:00:40 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.InstallMonetizer.Kolac.Installer.Meta (M)
16.7.9.8

File size:
1.2 MB (1,225,728 bytes)

Product version:
176.119.82.113

Copyright:
eWxXLSyPb

Trademarks:
tZjNw8

Original file name:
tinyinstall.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\bsu3y.exe

File PE Metadata
Compilation timestamp:
7/9/2016 8:25:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:eiKjtgASwRGupeZZ2/YuYh5GrXPRZOHgWr5QYQw9i+LBzBKR70zkx1iNas/GW6Ra:iK5wRzper2wbiCH7zvS1iNi3oqqpgk

Entry address:
0xB671

Entry point:
E8, 52, 41, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, C7, 01, E8, 54, 41, 00, E9, 10, 14, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, E8, 54, 41, 00, E8, FD, 13, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, CC, E9, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08...
 
[+]

Entropy:
7.5150

Code size:
75 KB (76,800 bytes)

The file bsu3y.exe has been seen being distributed by the following URL.

Remove bsu3y.exe - Powered by Reason Core Security