playpickle.com
Play Pickle
InstallX, LLC
Part of an InstallX (InstallIQ) installation, a PUP that may bundle additional adware on the computer. The file playpickle.com by InstallX has been detected as adware by 9 anti-malware scanners. According to Malwarebytes, this bundles additional adware offers via PlayPickle including toolbars such as Inbox.com, Babylon, Price Gong, Sendori, Price Peep and many others. PlayPickle uses the InstallIQ (InstallX) download manager to distribute such offers. The file has been seen being downloaded from dl5.iq7download.com.
Publisher:
Kitara Media LLC (signed by InstallX, LLC)
MD5:
a34f9ac02db16befe27814fb64d4c128
SHA-1:
3fbc6de9f1334f53143aea533acb7da976cc53a2
SHA-256:
668ee0e2a3d5fcd57457b10796ed23dfbc8244c35ad2906f87493a87c67e18f2
Scanner detections:
9 / 68
Explanation:
Uses the InstallIQ (by InstallX) software bundler that may include toolbars and other browser extensions offers.
Analysis date:
11/4/2024 4:58:10 PM UTC (today)
Scan engine
Detection
Engine version
Boost by Reason
Adware.InstallX.N
2013.8.29.4
Dr.Web
Adware.W3i.32
9.0.1.0241
ESET NOD32
Win32/InstallIQ (variant)
7.8706
IKARUS anti.virus
AdWare.InstallIQ
t3scan.2.0.127
Malwarebytes
PUP.PlayPickle
v2013.08.29.04
McAfee
Artemis!A34F9AC02DB1
5600.7181
Reason Heuristics
PUP.InstallX.N
14.8.7.17
Trend Micro House Call
TROJ_GEN.F47V0815
7.2.241
VIPRE Antivirus
InstallIQ Installer
20692
File size:
1.8 MB (1,907,792 bytes)
Product version:
2.133.0.0
Copyright:
Kitara Media LLC
Original file name:
playpickle.com
Language:
English (United States)
Common path:
C:\users\{user}\downloads\playpickle.com
Valid from:
3/21/2013 5:00:00 PM
Valid to:
3/26/2014 5:00:00 AM
Subject:
CN="InstallX, LLC", O="InstallX, LLC", L=Sartell, S=Minnesota, C=US
Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US
Serial number:
030985B5A39F75A13A497DAB8BF611F7
CTPH (ssdeep):
24576:dzWJ69qM6xE3IFu8jUIlYWM5ptIT8hdiUrT8mEdzvw1coPF/BJhFvvtg+N/9ppAF:diHycM1+7dzvw1coPFTvS+pHpA6TrUKq
The file playpickle.com has been seen being distributed by the following URL.