game of thrones season 1,2,3 english subs for dvdrips (pal).exe

Vasiliy Ryabchenko

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application game of thrones season 1,2,3 english subs for dvdrips (pal).exe, “Installer for Wideblue installer” by Vasiliy Ryabchenko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
Wideblue installer  (signed by Vasiliy Ryabchenko)

Product:
Wideblue installer

Description:
Installer for Wideblue installer

Version:
2014.6.29.1256

MD5:
cca8f9d681d9a123c508daf49c3373c3

SHA-1:
d5c4a6274b825752059c8451f4ef2c479a632b14

SHA-256:
3b2a1ea2f4333b9fa30c1763fa085e1b4fbea4efe64f93df1a6433e9e1f9fcab

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
1/12/2025 5:07:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware (M)
16.9.12.13

File size:
315.3 KB (322,832 bytes)

Product version:
1.0.0.3

Copyright:
Copyright © 2014 Wideblue installer

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Common path:
C:\users\{user}\downloads\game of thrones season 1,2,3 english subs for dvdrips (pal).exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
6/23/2014 6:04:12 AM

Valid to:
6/23/2015 6:04:12 AM

Subject:
E=Vasiliy.Ryabchenko@hotmail.com, CN=Vasiliy Ryabchenko, O=Vasiliy Ryabchenko, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
164AE16E5A8721C1FAA10425E76ADE9C

File PE Metadata
Compilation timestamp:
3/12/2013 4:51:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:or8bUzkuvcBYC47l2xkxUtI+u+wJBfhdWDtSJP5CDpCK3:orBkuveY3+u+OYDtS7CpCK3

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=367594874&publisher_id=675&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=1102784622&external_id=0&session_id=2205569244&hardware_id=2573164118&installer_file_name=game+of+thrones+season+1,2,3+english+subs+for+dvdrips+(pal)