pricepeep_50001_1001.exe

betwikx

The application pricepeep_50001_1001.exe by betwikx has been detected as a potentially unwanted program by 24 anti-malware scanners. This is a setup program which is used to install the application. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from installs.peepsrv.com.
Publisher:
betwikx  (signed and verified)

MD5:
a7fdb6d2ea8f5da2721f91e09312ef0a

SHA-1:
bc5d101e24237c95c430d25bd576480dcd73cd30

SHA-256:
16d34bf991820c27fced3898183d7c77a56369af639d6de506d4d3d12de19d7b

Scanner detections:
24 / 68

Status:
Potentially unwanted

Analysis date:
5/7/2024 4:28:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PricePeep.B
1135

Agnitum Outpost
Adware.PricePeep
7.1.1

AVG
Generic5
2014.0.3613

Bitdefender
Adware.PricePeep.B
1.0.20.1800

Bkav FE
W32.Clode5d.Trojan
1.3.0.4613

Dr.Web
Adware.Shopper.297
9.0.1.0360

Emsisoft Anti-Malware
Adware.PricePeep
8.13.12.26.11

ESET NOD32
Win32/AdWare.PricePeep (variant)
7.9272

Fortinet FortiGate
Adware/JS_PricePeep
12/26/2013

F-Secure
Adware.PricePeep.B
11.2013-26-12_5

G Data
Adware.PricePeep
13.12.22

IKARUS anti.virus
not-a-virus:AdWare.JS.PricePeep
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.175.10794

Kaspersky
not-a-virus:AdWare.JS.PricePeep
14.0.0.4560

Malwarebytes
PUP.Optional.PricePeep.A
v2013.12.26.11

McAfee
Artemis!A7FDB6D2EA8F
5600.7269

MicroWorld eScan
Adware.PricePeep.B
14.0.0.1080

NANO AntiVirus
Trojan.Win32.Shopper.csbcse
0.28.0.57029

nProtect
Adware.PricePeep.B
14.01.09.01

Panda Antivirus
Suspicious file
13.12.26.11

Reason Heuristics
PUP.betwikx.U
14.2.16.8

Trend Micro House Call
TROJ_GEN.F47V1222
7.2.360

Vba32 AntiVirus
AdWare.JS.PricePeep
3.12.24.3

VIPRE Antivirus
Pinball Corporation
25270

File size:
562.6 KB (576,152 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\pricepeep_50001_1001.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/17/2013 2:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=betwikx, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=betwikx, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7C2D7B2CD0E4304F2FDED654D7916B93

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:AxBS2+VXcwEWLgLEx1c8UadiEH2w31Rjf3d7ajwDavL:A7G/EWsLX8Uls2QojwDaT

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Code size:
23 KB (23,552 bytes)

The file pricepeep_50001_1001.exe has been seen being distributed by the following URL.

Remove pricepeep_50001_1001.exe - Powered by Reason Core Security