fpainstaller.exe

Ziftr Alerts - formerly FreePriceAlerts.com

myVBO LLC

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application fpainstaller.exe, “Installer for Ziftr Alerts - formerly FreePriceAlerts.com” by myVBO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
myVBO LLC  (signed and verified)

Product:
Ziftr Alerts - formerly FreePriceAlerts.com

Description:
Installer for Ziftr Alerts - formerly FreePriceAlerts.com

Version:
2013.5.16.1543

MD5:
5cbdd8f3eedd018b30f130d5fb5d66ea

SHA-1:
94ff3e324ea9e1ceb439a5d1e668ca3af5942407

SHA-256:
ed3877fb8ed2fe9a195eb6881728d74245d4f45658c958dff4f728987bb433d6

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
4/25/2024 10:36:38 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.WebPick.Installer (M)
16.1.1.6

File size:
2.3 MB (2,369,552 bytes)

Product version:
3.1.0

Copyright:
Copyright © 2012 myVBO LLC

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\fpainstaller.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/5/2013 8:00:00 PM

Valid to:
5/11/2015 7:59:59 PM

Subject:
CN=myVBO LLC, OU=FreePriceAlerts, O=myVBO LLC, L=Peterborough, S=New Hampshire, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6839CFCEA583E27C0222A8CEDE5E2DAF

File PE Metadata
Compilation timestamp:
2/4/2013 4:49:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:uircKY9gA8F+ycF/wcPOOn+KtXUkTE2ykwqroL5C3S:uitYeA8F+x2iyiLyIeC3S

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9988

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove fpainstaller.exe - Powered by Reason Core Security