bunndleoffermanager.dll

Bunndle Offer Manager

Bunndle, Inc.

The module bunndleoffermanager.dll, “Bunndle Offer Manager v2.0.0.7” by Bunndle has been detected as adware by 3 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Bunndle, Inc.  (signed and verified)

Product:
Bunndle Offer Manager

Description:
Bunndle Offer Manager v2.0.0.7

Version:
2.0.0.7

MD5:
f09bb97b9b8e2048fe562e78f761a0b7

SHA-1:
a7243e5768aea8717b22a6c7f0b144c5876dfe0f

SHA-256:
f65e438aa098d9e5742821763d355939724e923ea418ca7443439e7a409ba808

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
4/24/2024 2:34:03 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Adware.Bunndle.T
2013.8.28.21

ESET NOD32
Win32/Bunndle (variant)
7.9190

Reason Heuristics
PUP.Bunndle.T
14.8.7.20

File size:
339.3 KB (347,392 bytes)

Product version:
2.0.0.7

Copyright:
Copyright 2011 Bunndle, Inc. All rights reserved.

Original file name:
BunndleOfferManager

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bunndleoffermanager.dll

Digital Signature
Signed by:

Subject:
CN="Bunndle, Inc.", O="Bunndle, Inc.", L=Palo Alto, S=CA, C=US

Serial number:
07A17A4A60673F

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
6144:7yv0RMsT8lzZZOC4+OeO+OeN7VBBhhBBrXLsbg+vwzlTMw/8ZL8ITe:cYrAZOC4+OeO+OeNhBBhhBBzLsbg+vwd

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, ED, 46, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 6A, 0A, 6A, 00, FF, 75, 08, E8, 26, 49, 00, 00, 83, C4, 0C, 5D, C3, 8B, FF, 55, 8B, EC, 5D, E9, DF, FF, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 10, 00, 75, 04, 33, C0, 5D, C3, 8B, 55, 0C, 8B, 4D, 08, FF, 4D, 10, 74, 15, 0F, B7, 01, 66, 85, C0, 74, 0D, 66, 3B, 02, 75, 08, 83, C1, 02, 83, C2, 02, EB, E6, 0F, B7, 01, 0F, B7, 0A, 2B, C1, 5D, C3, 8B, FF, 55...
 
[+]

Entropy:
6.3053

Remove bunndleoffermanager.dll - Powered by Reason Core Security