birdy - light me up mp3.exe

Daneil Jemoch

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application birdy - light me up mp3.exe, “Installer for BlueOcean” by Daneil Jemoch has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The file has been seen being downloaded from mp3monkey.net. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
BlueOcean  (signed by Daneil Jemoch)

Product:
BlueOcean

Description:
Installer for BlueOcean

Version:
2014.6.25.1556

MD5:
b2b3c443809e22a37e443c4df03333d3

SHA-1:
09c4524db5d057d36a803c81444e244a17304f66

SHA-256:
e753fce6be205c08b42785909819557724bfb3d7089cb3f659c497f7837caa08

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
11/6/2024 8:22:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.WebPick.Installer (M)
16.1.23.17

File size:
327.8 KB (335,616 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 BlueOcean

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Common path:
C:\users\{user}\downloads\birdy - light me up mp3.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/1/2013 7:00:00 PM

Valid to:
9/2/2014 6:59:59 PM

Subject:
CN=Daneil Jemoch, O=Daneil Jemoch, STREET=Dubenskay 3, L=Kiev, S=Kiev, PostalCode=03056, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
49A39B9858F6FBAB7EFD6CE450878DDB

File PE Metadata
Compilation timestamp:
3/12/2013 2:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:7rObUzkuvcBYC47l2xDYcA/T6cMtphv6JZOrfDxIf/AbwkQ/qI91u:7rnkuveY3qYcArAcJ0ryf4ckQiI91u

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9272

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file birdy - light me up mp3.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=52018394&publisher_id=201&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=156055182&external_id=0&session_id=312110364&hardware_id=364128758&installer_file_name=birdy+-+light+me+up+mp3

Remove birdy - light me up mp3.exe - Powered by Reason Core Security