san.andreas.quake.2015.720p.brrip.x264.yify_10924_i12693882_il345.exe

Runner Utility

BERSHNET LLC

The application san.andreas.quake.2015.720p.brrip.x264.yify_10924_i12693882_il345.exe by BERSHNET has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from downprov.brown1switch.com.
Publisher:
Dummy, Ltd.  (signed by BERSHNET LLC)

Product:
Runner Utility

Version:
1.0.0.187

MD5:
359b3e71f1179fe87df72341e8b86f61

SHA-1:
bca682e5987cee937b4c93e62b809b15b5fadfc6

SHA-256:
f90c3fa9921d4e30ac92aca44943a80a2a92c6790f4e5cd08b8fea619949b51d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 6:35:52 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize (M)
16.8.11.1

File size:
1.5 MB (1,568,784 bytes)

Product version:
1.0.0.187

Copyright:
Copyright (C) 2013

Original file name:
runner.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\san.andreas.quake.2015.720p.brrip.x264.yify_10924_i12693882_il345.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/6/2015 12:00:00 AM

Valid to:
2/6/2016 11:59:59 PM

Subject:
CN=BERSHNET LLC, O=BERSHNET LLC, STREET="st. 600-richya b.66, of.10", L=Vinnitsya, S=Vinnitskaya, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E2D6C6F8DDF832E09DCF766B299AD2A9

File PE Metadata
Compilation timestamp:
5/27/2015 1:23:07 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:JXARSPOlcjyC55grgl2D4SnNCSO1QP+ewScI4Lh5BRndVYlZHHLKFUNVP:J5t2Cnl1SnNCHQP3M5z3Y7LKFwZ

Entry address:
0x37D8E5

Entry point:
60, E9, BC, 2F, FF, FF, 9C, 9C, 10, D2, C6, 04, 24, 46, E8, 27, 68, F0, FF, 66, 0F, BE, C2, 53, 60, 8D, 05, 34, C0, 76, 00, 60, 66, 89, 0C, 24, C7, 44, 24, 3C, 30, A7, 76, 00, 53, 88, 04, 24, C6, 04, 24, 75, FF, 30, 8F, 44, 24, 3C, 9C, 88, 34, 24, 9C, FF, 74, 24, 44, C2, 48, 00, 30, D6, E8, 49, 4D, F0, FF, 88, 45, FE, 88, 6C, 24, 0C, 88, 54, 24, 10, C7, 04, 24, 97, D9, F1, 2F, 66, 89, 44, 24, 04, 8D, 64, 24, 60, E9, 4E, C0, FE, FF, 29, 55, E8, 29, 55, E4, 8B, 10, C1, EA, 05, 29, 10, E8, C4, 24, 00, 00, F9...
 
[+]

Entropy:
7.9941

Packer / compiler:
ASProtect v1.1, 0xBRS

Code size:
187.5 KB (192,000 bytes)

The file san.andreas.quake.2015.720p.brrip.x264.yify_10924_i12693882_il345.exe has been seen being distributed by the following URL.