a+commonsense+guide+to+grammar+and.rar_10924_i52201400_il345.exe

Runner Utility

LLC Arctic West

The executable a+commonsense+guide+to+grammar+and.rar_10924_i52201400_il345.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
Dummy, Ltd.  (signed by LLC Arctic West)

Product:
Runner Utility

Version:
1.0.0.151

MD5:
6148e94a9e6e4b80016e0e7078bfd1af

SHA-1:
bc57d8c6591685428c6a1787e7204c00840d68bc

SHA-256:
62b56e633d3d72ec8e4fe684ccdef003691d83f784bc1672fa8d1ddd6225cdf9

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 4:27:42 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.28.15

File size:
1.9 MB (2,043,904 bytes)

Product version:
1.0.0.151

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\a+commonsense+guide+to+grammar+and.rar_10924_i52201400_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/24/2015 5:00:00 PM

Valid to:
8/24/2016 4:59:59 PM

Subject:
CN=LLC Arctic West, O=LLC Arctic West, STREET=Lviv highway 1, L=Mikolaiv, S=Lvovskaja, PostalCode=81600, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
416057CF015B4832DC973BA203AAB312

File PE Metadata
Compilation timestamp:
8/30/2015 8:13:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:+MH7EBM9zyD663a9q594vakEYQvY64v0KnbhC6qZxV3NY9vy:nOus6aa9qfwaLYvvrDqgM

Entry address:
0x410C66

Entry point:
68, 28, 24, 69, 9C, E8, 76, 85, E2, FF, D1, 2C, 29, 95, A9, 88, C4, 3A, 51, F7, 0F, 5E, F6, 3F, B8, 4A, 24, 33, CD, 6E, 06, 04, 60, 73, 26, 07, C8, 56, 61, 44, 37, BB, 0F, DB, 1C, 08, 1A, FC, 80, 34, D9, EF, 4F, C5, C6, AF, C2, 77, 2A, 83, 3E, 1C, 97, 0A, 1D, 67, 5A, 1F, BD, 73, BE, BA, 42, B5, AD, 6E, 86, 86, C9, 26, 91, A5, A0, FD, F0, 4A, C6, AA, 8F, 77, D0, 09, C0, 04, 97, 8B, ED, B9, A7, 02, F2, 34, F9, 11, 04, 8D, 36, 80, 1C, E9, F1, 14, 20, E5, 0E, 49, 68, 96, 4E, CE, C0, 67, 31, 11, 4C, 60, 12, 55...
 
[+]

Entropy:
7.9923  (probably packed)

Code size:
1.9 MB (2,032,640 bytes)