pricepeep_510001_0101.exe

betwikx

The application pricepeep_510001_0101.exe by betwikx has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from installs.peepsrv.com.
Publisher:
betwikx  (signed and verified)

MD5:
0df80cb92673f9f937a99dea0bbe8852

SHA-1:
4988e1112ba228c509200e8e4d8520e6446da0e3

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
5/7/2024 5:23:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PricePeep.A
1118

AVG
SmartShopper.L
2015.0.3596

Bitdefender
Adware.PricePeep.A
1.0.20.65

Bkav FE
W32.Clod6c2.Trojan
1.3.0.4562

Comodo Security
ApplicUnwnt
17382

Dr.Web
Adware.Shopper.297
9.0.1.013

Emsisoft Anti-Malware
Adware.PricePeep
8.14.01.13.06

Fortinet FortiGate
Adware/JS_PricePeep
1/13/2014

F-Secure
Adware.PricePeep.A
11.2014-13-01_2

G Data
Adware.PricePeep
14.1.22

Kaspersky
not-a-virus:AdWare.JS.PricePeep
14.0.0.4474

Malwarebytes
Adware.Agent
v2014.01.13.06

McAfee
Artemis!0DF80CB92673
5600.7252

MicroWorld eScan
Adware.PricePeep.A
15.0.0.39

nProtect
Trojan-Clicker/W32.Agent.589680
13.12.04.01

Reason Heuristics
PUP.betwikx.V
14.2.21.16

Rising Antivirus
PE:Trojan.Dropper!6.3CE
23.00.65.14111

Trend Micro House Call
TROJ_GEN.F47V1106
7.2.13

Vba32 AntiVirus
AdWare.JS.PricePeep
3.12.24.3

VIPRE Antivirus
Pinball Corporation
23996

File size:
575.9 KB (589,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\pricepeep_510001_0101.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/17/2013 2:00:00 AM

Valid to:
12/17/2015 12:59:59 AM

Subject:
CN=betwikx, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=betwikx, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7C2D7B2CD0E4304F2FDED654D7916B93

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:exBLMblgoaLrxst52tqWU9bij+S5CkWXSX6OOY34KKXDzBXID6aoCz:e7LMbahslij5AJOOJKKTzBXIOzCz

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file pricepeep_510001_0101.exe has been seen being distributed by the following URL.

Remove pricepeep_510001_0101.exe - Powered by Reason Core Security