1_offer_6.exe

betwikx

The application 1_offer_6.exe by betwikx has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from installs.peepsrv.com.
Publisher:
betwikx  (signed and verified)

MD5:
074e39606f1c0ff31d95ba34ddb6742f

SHA-1:
868dfe9aee7e7d383a3064ce7b365f8566096f5f

SHA-256:
054ba97d700d52e04082f2e0d9d841a31a68a4a6697a7f90c87f7dcc0cfa41d1

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
5/8/2024 12:56:59 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic5
2015.0.3593

Dr.Web
Adware.Shopper.297
9.0.1.015

ESET NOD32
Win32/AdWare.PricePeep (variant)
8.9272

IKARUS anti.virus
not-a-virus:AdWare.JS.PricePeep
t3scan.2.2.29

Kaspersky
not-a-virus:AdWare.JS.PricePeep
14.0.0.4462

Malwarebytes
PUP.Optional.PricePeep.A
v2014.01.15.02

Reason Heuristics
PUP.betwikx.J
14.2.21.20

VIPRE Antivirus
Pinball Corporation
25274

File size:
560 KB (573,464 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\1_offer_6.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/17/2013 1:00:00 AM

Valid to:
12/16/2015 11:59:59 PM

Subject:
CN=betwikx, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=betwikx, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7C2D7B2CD0E4304F2FDED654D7916B93

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:6xBLuaBeH65RfWN9IEw6570d4RyelsWK/EjjK2E:679eH6q9bwd3elK/wK2E

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9483

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file 1_offer_6.exe has been seen being distributed by the following URL.

Remove 1_offer_6.exe - Powered by Reason Core Security