ipad_10924_i439860_il345.exe

Runner Utility

BERSHNET LLC

The application ipad_10924_i439860_il345.exe by BERSHNET has been detected as adware by 21 anti-malware scanners. It bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
bda18f43c8fd08564758e12bb129a9de

SHA-1:
9890e9be5084647c9e5be76226be279b8079df7d

SHA-256:
cb9ad288f9a854a4fbd75bdcc686bebc5093d12daa77663dd7874240155b2364

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
4/20/2024 12:19:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.597354
657

AhnLab V3 Security
PUP/Win32.LoadMoney
2015.04.19

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

AVG
Generic
2016.0.3135

Bitdefender
Gen:Variant.Kazy.597354
1.0.20.545

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.LoadMoney.IARS
21814

Dr.Web
Trojan.Amonetize
9.0.1.0109

Emsisoft Anti-Malware
Gen:Variant.Kazy.597354
8.15.04.19.06

ESET NOD32
Win32/Amonetize.DW potentially unwanted (variant)
9.11495

F-Prot
W32/S-53544127
v6.4.7.1.166

F-Secure
Gen:Variant.Kazy.597354
11.2015-19-04_1

G Data
Gen:Variant.Kazy.597354
15.4.25

K7 AntiVirus
Unwanted-Program
13.202.15640

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.2169

Malwarebytes
PUP.Optional.Amonetize
v2015.04.19.06

MicroWorld eScan
Gen:Variant.Kazy.597354
16.0.0.327

Panda Antivirus
Trj/Genetic.gen
15.04.19.06

Qihoo 360 Security
HEUR/QVM16.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.BERSHNET
15.4.19.2

VIPRE Antivirus
Amonetize
39464

File size:
1.5 MB (1,544,208 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ipad_10924_i439860_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2015 1:00:00 AM

Valid to:
2/7/2016 12:59:59 AM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
4/18/2015 8:13:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:DZFwJpnlDP49ihAeOP+dbGg5ezJgEmu5pEsbEbbs+16iIGxwl5KAVkNFLSVO:4lDQ4hAeOPqV5ezKEmuHjhzi/xwl5xVo

Entry address:
0x2FB5B2

Entry point:
E8, CF, 41, 00, 00, 66, C7, 44, 24, 04, 00, 53, C7, 44, 24, 04, D9, C0, 66, 01, E9, E0, 48, 00, 00, 45, 10, 46, 51, 5C, DF, 5E, 09, 96, 2D, 45, 18, 62, 33, 5D, 10, C1, CC, A4, E3, 74, 0D, 7D, 32, E9, AD, 80, 37, D6, D2, EB, CC, B9, E9, F9, 8E, 84, A7, B9, CA, 67, D1, 18, 30, 79, 11, 10, B2, 8D, E2, A3, 91, D0, 91, CF, 96, E0, A9, EF, AE, 33, 5A, 1A, 59, 30, 86, 64, B5, 7A, 67, 56, CE, B4, F1, A3, E8, F7, FC, CE, 9B, 7E, 11, C6, 7C, B3, 5E, 49, EB, 34, 96, 49, 63, E1, 9C, B4, 30, 1D, 6F, 1E, 33, EF, B0, BB...
 
[+]

Entropy:
7.9939  (probably packed)

Code size:
187.5 KB (192,000 bytes)

Remove ipad_10924_i439860_il345.exe - Powered by Reason Core Security