muzyka v kontakte - electro mix 2013 krasivaya muzyka iplayer fm.exe

Bunndle Stand-Alone Offer Manager, OM 2.4.0.0, 2013-09-18 11:24

IT River

The application muzyka v kontakte - electro mix 2013 krasivaya muzyka iplayer fm.exe, “Bunndle Stand-Alone Offer Manager” by IT River has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Bunndle, Inc.  (signed by IT River)

Product:
Bunndle Stand-Alone Offer Manager, OM 2.4.0.0, 2013-09-18 11:24

Description:
Bunndle Stand-Alone Offer Manager

Version:
1.0.0.4

MD5:
9eeb6b2a8ea3aa274b1ce9b3e640cb05

SHA-1:
7e35449f486b1ae94b0f47d44611f30abf4e3e5b

SHA-256:
8fe01b2f90d56b443add01f4d847d5a9247eab3e82b11d1b845845b6573c036c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 12:08:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ITRiver (M)
16.2.13.7

File size:
551.4 KB (564,584 bytes)

Product version:
1.0.0.4

Copyright:
Copyright 2013 Bunndle, Inc. All rights reserved.

Original file name:
BunndleOfferManager

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\muzyka v kontakte - electro mix 2013 krasivaya muzyka iplayer fm.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/25/2014 2:00:00 AM

Valid to:
2/26/2015 1:59:59 AM

Subject:
CN=IT River, O=IT River, STREET="Obolenskiy, 9", L=Moscow, S=Moscow oblast, PostalCode=119021, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0F02E0C593A3B9A15B22F5853C90D66B

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:28av2m349iKlAKw8FriyGMLAM9CNVrr4d5S4zD9oo/JVqc:7arc/wmiyJLx9CNVrr4nS4zvJVqc

Entry address:
0x1664

Entry point:
83, 3D, 78, 30, 47, 00, F7, 75, 19, 89, 35, 32, 30, 47, 00, 89, 05, AD, 30, 47, 00, C6, 05, E9, 30, 47, 00, 40, 89, 15, 21, 30, 47, 00, BE, B8, 10, 40, 00, 89, 35, 10, 60, 47, 00, E9, AA, FB, FF, FF, 8B, 05, 6A, 30, 47, 00, 01, 15, 38, 30, 47, 00, C7, 05, 85, 30, 47, 00, DC, 3C, 01, 00, C3, 8D, 40, 00, 55, 8B, EC, 83, C4, D4, 89, 45, FC, 89, 7C, 24, DC, 39, 45, EE, 7E, 19, 89, 35, 1B, 30, 47, 00, 8D, 15, 24, 30, 47, 00, C7, 42, 28, 9B, 00, 00, 00, 89, 35, F2, 30, 47, 00, C6, 05, A4, 30, 47, 00, 8C, 89, 0D...
 
[+]

Code size:
456 KB (466,944 bytes)