unins000.exe

First Offer LTD

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions which inject ads in the browser. The application unins000.exe by First Offer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex installer. This is the uninstaller utility registered in the Windows Control Panel for the program PriceCongress 6.8 by SimplyTech LTD. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
First Offer LTD  (signed and verified)

Description:
Setup/Uninstall

Version:
51.1052.0.0

MD5:
4e5bead8b077edae89da733f482fc4c6

SHA-1:
e56b6ef14ebbe75e17bac00d17ad2416664e0226

SHA-256:
ad1ced6ddee7c7eecef62d16d3b1e97ffa9eb4f15300951963bf8abba33fe64d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 2:33:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.FirstOffer.Bundler (M)
16.3.4.14

File size:
1.2 MB (1,255,496 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\Program Files\pricecongress\unins000.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/8/2013 2:00:00 AM

Valid to:
10/9/2014 1:59:59 AM

Subject:
CN=First Offer LTD, O=First Offer LTD, STREET=Habarzel 21 Tel Aviv, L=Tel aviv, S=Israel, PostalCode=69710, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
49900242461D96CB7B045BE0A258338E

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:51 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qh+EpSGP3ZEgRhuRKOODzjJBwjOGfcCUWgEf0ZsMCmG2Hx91B:4a+PjJaEWZAsT6N

Entry address:
0xFAF7C

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, 57, B8, A4, 94, 4F, 00, E8, AD, DF, F0, FF, 6A, EC, A1, 7C, ED, 4F, 00, 8B, 00, 8B, 98, 70, 01, 00, 00, 53, E8, 40, EE, F0, FF, 25, 7F, FF, FF, FF, 50, 6A, EC, A1, 7C, ED, 4F, 00, 53, E8, 95, F0, F0, FF, 33, C0, 55, 68, F7, AF, 4F, 00, 64, FF, 30, 64, 89, 20, 6A, 01, E8, E8, E7, F0, FF, E8, 17, E2, FF, FF, A1, DC, 90, 4F, 00, 50, 68, 40, 91, 4F, 00, A1, 7C, ED, 4F, 00, 8B, 00, E8, 50, 0E, F8, FF, E8, 6B, E2, FF, FF, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 19, E9, E4, 96, F0, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
999 KB (1,022,976 bytes)

Program Uninstaller
Program name:
PriceCongress 6.8

Display publisher:
SimplyTech LTD

Display version:
6.8

Uninstall string:
"C:\Program Files\PriceCongress\unins000.exe"


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove unins000.exe - Powered by Reason Core Security