safeip 2.0.0.2057 portable.exe

Boris Burkin

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application safeip 2.0.0.2057 portable.exe, “Installer for TopApp software” by Boris Burkin has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
TopApp software  (signed by Boris Burkin)

Product:
TopApp software

Description:
Installer for TopApp software

Version:
2014.5.23.1127

MD5:
8299d773cabbbd11abafdb18785c0525

SHA-1:
f77a3273a8e4a1a181a47c0f5bb16917b9179cca

SHA-256:
c7c84486d21daf7940a2e3dfbdafca9f7c391c24c829920066c2305a254923f8

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
4/18/2024 10:18:16 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/AntiFW.b.109
7.11.151.96

avast!
Win32:InstalleRex-BT [Trj]
140525-0

AVG
Generic
2015.0.3464

Comodo Security
Application.Win32.InstalleRex.KG
18318

Dr.Web
Adware.Downware.2108
9.0.1.0145

ESET NOD32
Win32/InstalleRex.M potentially unwanted application
7.0.302.0

Kaspersky
Trojan.Win32.AntiFW
14.0.0.3814

Malwarebytes
PUP.Optional.InstalleRex
v2014.05.25.04

NANO AntiVirus
Riskware.Win32.InfoLeak.cvgqot
0.28.0.59921

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Quick Heal
Trojan.AntiFW.A5
5.14.14.00

Reason Heuristics
Adware.WebPick.Installer.Z
14.6.12.9

Sophos
InstallRex
4.98

Vba32 AntiVirus
Downloader.AdLoad
3.12.26.0

VIPRE Antivirus
Threat.4150696
29560

File size:
315.1 KB (322,632 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 TopApp software

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\safeip 2.0.0.2057 portable.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/19/2013 3:00:00 AM

Valid to:
9/20/2014 2:59:59 AM

Subject:
CN=Boris Burkin, O=Boris Burkin, STREET=Tankistiv 14, L=Kyiv, S=Kyivska, PostalCode=03061, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
033AD040336E8286DF7ACF4D4908361F

File PE Metadata
Compilation timestamp:
3/12/2013 11:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:8rYbUzkuvcBYC47l2xLnvhueEZdkKQ3+7Oj7hTOVA1HWZ9:8rdkuveY3CvI5Zdkj6OEu1HS9

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9537

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file safeip 2.0.0.2057 portable.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove safeip 2.0.0.2057 portable.exe - Powered by Reason Core Security