PricePeep.exe

PricePeep

PricePeep.com

The application PricePeep.exe has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from dmrm038s4vkzd.cloudfront.net and multiple other hosts.
Publisher:
PricePeep.com

Product:
PricePeep

Version:
1.0

MD5:
c926b246aa12d0edecec063a7e05e0dc

SHA-1:
a11f4a17a6d2ce826e3dcc51996aa2bf1a835311

SHA-256:
1ab645aaa5aa6e17054bbe71e621afb4edcabe60e691a3d72ba4fdb0fc8e4ac9

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
6/17/2024 2:04:04 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Agent
7.1.1

Avira AntiVirus
Adware/Agent.635597
7.11.110.236

AVG
AdInject.Betwikx
2014.0.3543

Baidu Antivirus
AdWare.Win32.Agent
4.0.3.131126

Bitdefender
Adware.PricePeep.A
1.0.20.1205

Boost by Reason
Optional.PricePeep.J
188163

Comodo Security
Heur.Suspicious
17215

Dr.Web
Adware.Shopper.297
9.0.1.0241

Emsisoft Anti-Malware
Adware.PricePeep
8.13.08.29.12

ESET NOD32
Win32/OutBrowse
7.9005

Fortinet FortiGate
Adware/Agent
8/29/2013

F-Secure
Adware.PricePeep.A
11.2013-26-11_3

G Data
Adware.PricePeep
13.8.22

IKARUS anti.virus
not-a-virus:AdWare.Win32.Agent
t3scan.2.0.127

K7 AntiVirus
Adware
13.173.10086

Kaspersky
not-a-virus:AdWare.JS.PricePeep
14.0.0.3808

Malwarebytes
Adware.Agent
v2013.08.29.12

MicroWorld eScan
Adware.Generic.458215
14.0.0.723

NANO AntiVirus
Trojan.Win32.Shopper.bsekot
0.26.0.55974

nProtect
Adware.PricePeep.A
13.11.01.03

Reason Heuristics
PUP.PricePeep.J
14.3.1.0

Rising Antivirus
Trojan.Win32.Generic.14AC22CD
23.00.65.131124

Trend Micro House Call
TROJ_GEN.R0CBH07J613
7.2.241

Trend Micro
ADW_HOTBAR
10.465.29

Vba32 AntiVirus
AdWare.Agent.adln
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
23052

File size:
620.7 KB (635,597 bytes)

Copyright:
© PricePeep

Trademarks:
PricePeep.com

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pricepeep.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:8yhKRXnet6LEkOLIv0nageZsh8x4X0X6OOYT4KKeH71Hgjt7iBCmsp4:81XnRVOL1a1ZtwrOOLKKa71HgJiBC4

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9249

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file PricePeep.exe has been seen being distributed by the following 3 URLs.

http://dmrm038s4vkzd.cloudfront.net/cl/inst/bundles/PricePeep_Outbrowse/.../PricePeep.exe

Remove PricePeep.exe - Powered by Reason Core Security