setup_playpickle_v1.exe

Installer

OI Software, Inc.

The application setup_playpickle_v1.exe by OI Software has been detected as adware by 24 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
OpenInstall   (signed by OI Software, Inc.)

Product:
Installer

Version:
1,15,0,963

MD5:
644bb03bc9fbe62b053699205b40ea9a

SHA-1:
5b8a3ddac4cc724ef937b760e372df8b67043209

SHA-256:
624797617e920a8fa6d967e2043e1eaabca22dc75072faebdeac5c48e1d1918a

Scanner detections:
24 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/19/2024 5:44:07 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.OpenInstall
7.1.1

Avira AntiVirus
Adware/Adware.237568.1
7.11.53.138

avast!
Win32:OpenInstall-H [PUP]
2014.9-160206

Baidu Antivirus
AdWare.Win32.OpenInstall
4.0.3.1626

Bitdefender
Application.Generic.383704
1.0.20.185

Comodo Security
Application.Win32.AdWare.OpenInstall.A
14506

Dr.Web
Adware.OpenInstall.1
9.0.1.037

Emsisoft Anti-Malware
Application.Generic.383704
8.16.02.06.07

ESET NOD32
Win32/OpenInstall (variant)
10.7789

Fortinet FortiGate
Riskware/OpenInstall
2/6/2016

F-Prot
W32/OpenInstall.B.gen
v6.4.7.1.166

F-Secure
Application.Generic.383704
11.2016-06-02_7

G Data
Application.Generic.383704
16.2.22

IKARUS anti.virus
AdWare.Adware
t3scan.1.1.122.0

K7 AntiVirus
Riskware
13.155.7980

Malwarebytes
PUP.BundleInstaller.OI
v2016.02.06.07

MicroWorld eScan
Application.Generic.383704
17.0.0.111

NANO AntiVirus
Riskware.Win32.OpenInstall.dfnxro
0.28.6.63474

Reason Heuristics
PUP.OpenInstall.OISoftware.Installer (M)
16.2.6.7

Sophos
4.84

SUPERAntiSpyware
Adware.OpenInstall
9340

Trend Micro House Call
TROJ_GEN.F47V1129
7.2.37

Vba32 AntiVirus
Signed-Adware.Hotbar
3.12.18.4

VIPRE Antivirus
Trojan.Win32.Generic
14430

File size:
231.1 KB (236,632 bytes)

Product version:
1,15,0,963

Copyright:
Copyright © 2010

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_playpickle_v1.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/29/2010 7:00:00 PM

Valid to:
11/30/2011 6:59:59 PM

Subject:
CN="OI Software, Inc.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="OI Software, Inc.", L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47E25BFB5C4E24A51FE4414067EF5CA5

File PE Metadata
Compilation timestamp:
10/25/2011 10:59:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
6144:goZ4T06i3TGpOM+Wjw0Obox/AgtzZQ6soZ:RAMM21bw/dzZgs

Entry address:
0x80AA0

Entry point:
60, BE, 00, E0, 44, 00, 8D, BE, 00, 30, FB, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.7493

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
204 KB (208,896 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove setup_playpickle_v1.exe - Powered by Reason Core Security