searcher.exe

LLC

The application searcher.exe by LLC has been detected as adware by 3 anti-malware scanners. This is a setup program which is used to install the application. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from sendme8.ru.
Publisher:
LLC   (signed and verified)

Version:
1.0.0.0

MD5:
6ed1812ba9657822fd8e3e78000f32de

SHA-1:
ac10cec4162c28ab1f4eadb216d91759859a9bb9

SHA-256:
8b0fac2246f7140e21eefb249c69936e941b52c93489ebb6305776f14b1da75c

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
11/15/2024 10:30:58 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Downloader
2016.0.2968

ESET NOD32
Win32/Homepager.A potentially unwanted (variant)
9.12337

Reason Heuristics
PUP.Amonitize (M)
15.10.2.17

File size:
5.5 MB (5,790,872 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\searcher.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/4/2015 3:00:00 AM

Valid to:
9/4/2016 2:59:59 AM

Subject:
CN="LLC ""SLOBODA PROYEKT""", OU=IT, O="LLC ""SLOBODA PROYEKT""", STREET="prosp MOSKOVSKIY, 144", L=Kharkiv, S=Kharkivska, PostalCode=61082, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00E491193F6531060F8FC69563B236D139

File PE Metadata
Compilation timestamp:
9/30/2015 7:49:37 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:PbEbyKP3dBQu8ljA5hjRajTG4yPvnSED26Hd:o3Hz86hNaj7/PI

Entry address:
0x3BE608

Entry point:
55, 8B, EC, 83, C4, E8, 33, C0, 89, 45, E8, 89, 45, EC, B8, A4, 03, 7B, 00, E8, 18, 15, C5, FF, 33, C0, 55, 68, DE, E6, 7B, 00, 64, FF, 30, 64, 89, 20, 8B, 0D, AC, D3, 7D, 00, A1, 80, DA, 7D, 00, 8B, 00, 8B, 15, 24, 8C, 7A, 00, E8, E6, AC, E2, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 59, 88, C4, FF, 8B, 45, EC, BA, F8, E6, 7B, 00, E8, 5C, CC, C4, FF, 75, 2B, A1, 80, DA, 7D, 00, 8B, 00, E8, A6, AC, E2, FF, A1, AC, D3, 7D, 00, 8B, 00, 8B, 40, 68, B2, 01, E8, 69, 28, DB, FF, A1, 80, DA, 7D, 00, 8B, 00, E8, FD...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.7 MB (3,919,360 bytes)

The file searcher.exe has been seen being distributed by the following URL.

Remove searcher.exe - Powered by Reason Core Security