cholov_k_ukr._p_snya___z_dnem_narodzhennya_v_ta_m__xmusic.me_.exe

ВERSHNET LLC

The application cholov_k_ukr._p_snya___z_dnem_narodzhennya_v_ta_m__xmusic.me_.exe by ВERSHNET has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from translatds.ru.
Publisher:
ВERSHNET LLC  (signed and verified)

Version:
1.0.0.0

MD5:
84b148912963590a0cf0c6383fecbf0d

SHA-1:
5f2f51ede14307969ef9b44621a1f3ba051a2c33

SHA-256:
9b1063f201329cdb70ed8b9d37a9ed8c1a4e1d3a85cf2bcf4e04624453fb025a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
5/7/2024 12:38:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse.ERSHNET (M)
16.3.24.18

File size:
3.6 MB (3,800,632 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\cholov_k_ukr._p_snya___z_dnem_narodzhennya_v_ta_m__xmusic.me_.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/5/2015 2:00:00 AM

Valid to:
2/6/2016 1:59:59 AM

Subject:
CN=ВERSHNET LLC, O=ВERSHNET LLC, STREET="600-Richchya, house 66, office 10", L=Vinnitsa, S=Vinnitskiy Region, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DCBDEF5E756334284571793EA14D465

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:Z71G4Fs0ExzJveTn14v5AwkeS6au4a5BJh:Z7sokxz3au4ajv

Entry address:
0xA82940

Entry point:
60, BE, 00, 60, B6, 00, 8D, BE, 00, B0, 89, FF, C7, 87, CC, 80, 78, 00, 47, A9, 08, 00, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
3.1 MB (3,264,512 bytes)

The file cholov_k_ukr._p_snya___z_dnem_narodzhennya_v_ta_m__xmusic.me_.exe has been seen being distributed by the following URL.