searcher.exe

LLC

The application searcher.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This file is typically installed with the program Searcher. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from sendme13.ru.
Publisher:
LLC   (signed and verified)

Version:
1.0.0.0

MD5:
d0ea1816a32b4fad1958733f9a80dca2

SHA-1:
ce10b11d0127f42539fc550833b13f378c604fdd

SHA-256:
0f2bfa424144c62d86b7e8d76058bee1034259fd2bd7a31a260758b9eb5d163d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/17/2024 12:46:49 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
15.11.7.10

File size:
5.5 MB (5,790,296 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\searcher.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/1/2015 3:00:00 AM

Valid to:
10/1/2016 2:59:59 AM

Subject:
CN="LLC ""AZ SOFT""", O="LLC ""AZ SOFT""", STREET="Vulytsya Dalnytska, Budynok 23/4, Ofis 310", L=Odesa, S=Odeska, PostalCode=65005, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3CCA67117AE7C5BE2F99ECBA3ECC9F69

File PE Metadata
Compilation timestamp:
11/6/2015 6:42:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:lbEbyKP3dBQu8ljA5hjRajo+4yPvnSED26Hx:K3Hz86hNajoP/P0

Entry address:
0x3BE608

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, E8, 89, 45, EC, B8, C8, 01, 7B, 00, E8, 18, 15, C5, FF, 33, C0, 55, 68, DE, E6, 7B, 00, 64, FF, 30, 64, 89, 20, 8B, 0D, AC, D3, 7D, 00, A1, 80, DA, 7D, 00, 8B, 00, 8B, 15, 64, 8A, 7A, 00, E8, E6, AC, E2, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 59, 88, C4, FF, 8B, 45, EC, BA, F8, E6, 7B, 00, E8, 5C, CC, C4, FF, 75, 2B, A1, 80, DA, 7D, 00, 8B, 00, E8, A6, AC, E2, FF, A1, AC, D3, 7D, 00, 8B, 00, 8B, 40, 68, B2, 01, E8, 69, 28, DB, FF, A1, 80, DA, 7D, 00, 8B, 00, E8, FD...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.7 MB (3,918,848 bytes)

The file searcher.exe has been discovered within the following program.

Searcher  by Searcher
About 1% of users remove it
 
Powered by Should I Remove It?

The file searcher.exe has been seen being distributed by the following URL.

Remove searcher.exe - Powered by Reason Core Security