braveland_wizard_v1.0_setup.exe

I n s t a l l e r P l u g i n

Evgen Kugitko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application braveland_wizard_v1.0_setup.exe by Evgen Kugitko has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. The file has been seen being downloaded from littlebyte.net. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
Alexander Roshan  (signed by Evgen Kugitko)

Product:
I n s t a l l e r P l u g i n

Version:
1.22.0

MD5:
1ed0c334fa1baeea45639c4a1881fd53

SHA-1:
627aa15d22429ee62592b1ae328e6f8e18c9e1e1

SHA-256:
30e6dc408d6df7b634750dd35866812f70cb83ea9ae3670b19d52b1b4126e8d5

Scanner detections:
23 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
6/28/2025 1:02:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.78027
5656960

Agnitum Outpost
PUA.FileTour
7.1.1

Avira AntiVirus
ADWARE/FileTour.Gen4
8.3.1.6

avast!
Win32:Adware-gen [Adw]
2014.9-150421

AVG
Generic
2016.0.3132

Bitdefender
Gen:Variant.Strictor.78027
1.0.20.555

Dr.Web
Trojan.DownLoader12.46405
9.0.1.0111

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.553305
8.15.04.21.04

ESET NOD32
Win32/Adware.FileTour.IP application
9.7.0.302.0

F-Prot
W32/S-bce73eb2
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Kazy
11.2015-21-04_3

G Data
Gen:Variant.Strictor.78027
15.4.25

IKARUS anti.virus
PUA.FileTour
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15663

Kaspersky
not-a-virus:AdWare.Win32.FakeInstaller
14.0.0.2156

MicroWorld eScan
Gen:Variant.Strictor.78027
16.0.0.333

Norman
Gen:Variant.Adware.Kazy.553305
11.20150616

Panda Antivirus
Trj/Genetic.gen
15.04.21.04

Reason Heuristics
Threat.Webpick.Bundler
15.4.21.12

Vba32 AntiVirus
AdWare.FakeInstaller
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
41056

Zillya! Antivirus
Adware.FileTour.Win32.103
2.0.0.2147

File size:
1.2 MB (1,287,912 bytes)

Copyright:
C o p y r i g h t © A l e x a n d e r R o s h al 1996-2014

Original file name:
I n s t a l l e r P l u g i n . e x e

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/24/2014 6:00:00 AM

Valid to:
9/25/2015 5:59:59 AM

Subject:
CN=Evgen Kugitko, OU=Individual Developer, O=No Organization Affiliation, L=Kiev, S=Kiev, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4179EA1BEC59D4CA7E66862832555480

File PE Metadata
Compilation timestamp:
6/20/1992 4:22:17 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qI5LXmY9qx/JVJ2XiKVs4JmxCAmr+0pd4XX7YfjNHKB8L:T2Y9whz2XiKf8pG+0pdirEjNHKo

Entry address:
0x2CD104

Entry point:
E9, 2E, 67, ED, FF, 00, 00, 53, 61, 66, 65, 41, 72, 72, 61, 79, 47, 65, 74, 4C, 42, 6F, 75, 6E, 64, 00, 9C, FF, 74, 24, 34, 8F, 45, 00, 88, 14, 24, 56, 9C, FF, 74, 24, 04, 8D, 64, 24, 44, E9, 20, 22, 00, 00, 66, 0F, BC, C2, D4, 6A, 8D, 87, EC, A2, BE, 5A, 89, E8, F6, C6, D9, 68, 5A, 36, E1, E3, 66, 85, D3, 83, ED, 04, 66, C7, 04, 24, D3, CE, E9, 1D, 24, 00, 00, 60, E9, 8F, 11, 00, 00, 88, 74, 24, 04, 66, 2D, 8B, FF, 0F, A3, D7, F5, 66, 31, C3, 88, 1C, 24, F8, E8, A5, 22, 00, 00, E9, B9, 09, 00, 00, 9C, 89...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
685.5 KB (701,952 bytes)

The file braveland_wizard_v1.0_setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove braveland_wizard_v1.0_setup.exe - Powered by Reason Core Security