playpickle.com

Play Pickle

InstallX, LLC

Part of an InstallX (InstallIQ) installation, a PUP that may bundle additional adware on the computer. The file playpickle.com by InstallX has been detected as adware by 9 anti-malware scanners. According to Malwarebytes, this bundles additional adware offers via PlayPickle including toolbars such as Inbox.com, Babylon, Price Gong, Sendori, Price Peep and many others. PlayPickle uses the InstallIQ (InstallX) download manager to distribute such offers. The file has been seen being downloaded from dl5.iq7download.com.
Publisher:
Kitara Media LLC  (signed by InstallX, LLC)

Product:
Play Pickle

Version:
2.133.0.0

MD5:
a34f9ac02db16befe27814fb64d4c128

SHA-1:
3fbc6de9f1334f53143aea533acb7da976cc53a2

SHA-256:
668ee0e2a3d5fcd57457b10796ed23dfbc8244c35ad2906f87493a87c67e18f2

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallIQ (by InstallX) software bundler that may include toolbars and other browser extensions offers.

Analysis date:
11/4/2024 4:58:10 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Adware.InstallX.N
2013.8.29.4

Dr.Web
Adware.W3i.32
9.0.1.0241

ESET NOD32
Win32/InstallIQ (variant)
7.8706

IKARUS anti.virus
AdWare.InstallIQ
t3scan.2.0.127

Malwarebytes
PUP.PlayPickle
v2013.08.29.04

McAfee
Artemis!A34F9AC02DB1
5600.7181

Reason Heuristics
PUP.InstallX.N
14.8.7.17

Trend Micro House Call
TROJ_GEN.F47V0815
7.2.241

VIPRE Antivirus
InstallIQ Installer
20692

File size:
1.8 MB (1,907,792 bytes)

Product version:
2.133.0.0

Copyright:
Kitara Media LLC

Original file name:
playpickle.com

Language:
English (United States)

Common path:
C:\users\{user}\downloads\playpickle.com

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/21/2013 5:00:00 PM

Valid to:
3/26/2014 5:00:00 AM

Subject:
CN="InstallX, LLC", O="InstallX, LLC", L=Sartell, S=Minnesota, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
030985B5A39F75A13A497DAB8BF611F7

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:dzWJ69qM6xE3IFu8jUIlYWM5ptIT8hdiUrT8mEdzvw1coPF/BJhFvvtg+N/9ppAF:diHycM1+7dzvw1coPFTvS+pHpA6TrUKq

The file playpickle.com has been seen being distributed by the following URL.

Remove playpickle.com - Powered by Reason Core Security