microsoft toolkit 2.5 final, activator for windows and office free download.exe

YL production

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application microsoft toolkit 2.5 final, activator for windows and office free download.exe, “Installer for BrilliantInstaller” by YL production has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
BrilliantInstaller  (signed by YL production)

Product:
BrilliantInstaller

Description:
Installer for BrilliantInstaller

Version:
2014.6.4.1630

MD5:
da88bdc5f9592d740f69665d5a9bfad1

SHA-1:
6de8941d0fe2b551a6f902152d20a97d636b7e4c

SHA-256:
dbd0ae74a8059685f3f919b3837cf26300859e66ff52c8f74b9251cb2584e81a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
5/7/2024 8:56:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.WebPick.Installer (M)
16.2.5.22

File size:
315 KB (322,600 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 BrilliantInstaller

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\microsoft toolkit 2.5 final, activator for windows and office free download.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
1/16/2014 1:49:26 PM

Valid to:
1/16/2015 1:49:26 PM

Subject:
E=Lebedev72@hotmail.com, CN="Open Source Developer, Yuri LEBEDEV", O=YL production, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
284B7B8274AFC7E851A73B98B619311F

File PE Metadata
Compilation timestamp:
3/12/2013 3:51:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:2r2bUzkuvcBYC47l2xib6HwzFyytCr88oDG1GI25i1snqq08Dr:2r/kuveY3dGwUECr88oDG1GIS+bq08n

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9527

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)