0867b415-0eb1-b711-927f-a038e593a825_1d1c32e26d3b852

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The file 0867b415-0eb1-b711-927f-a038e593a825_1d1c32e26d3b852, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
bddb545e61a4cfd74c92d6a960b1fafe

SHA-1:
f26d36d68defa0c83049046ab4764ed7ecf3bf78

SHA-256:
88f4ca3713656d1eb70daae20a66ad83c857e6cca00c99897b7ba4c526ae86a5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 4:30:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.16

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\ProgramData\microsoft\microsoft antimalware\scans\filesstash\0867b415-0eb1-b711-927f-a038e593a825_1d1c32e26d3b852

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:WCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:WrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file 0867b415-0eb1-b711-927f-a038e593a825_1d1c32e26d3b852 has been seen being distributed by the following 46 URLs.

http://www.contentdownloadmega.com/WVl6OTRQV2RXUTNwdllsQllkV0ZJU25sWE5saGpiR3d6UmxkTlJ6UnNVWHBMUlRGbk5uZ3pUakI2TlNVeVJuWk1UU1V6UkNaalBXWjFXRTEyVFVZMFNYQTNURWxxZFhoUWQySlNRa2RMSlRKR0pUSkdTamhZZWxoaWJFbExVbFI1WWxaQ05GUk5hVlZKU1hGdVdHTlZOM1J2Y2sxbloyZzBkRXBhVlZkeGQxUnJNVWh4TjNSdlQzUmxkalJsTUVGU1VIRmpSemxuU2xsdVNXZDRObGhWU0VjNGNHc2xNa1kwZVd0WVRGaFFTVE14SlRKR1pUZFhaMFpUVjFKVWJVRWxNa1pNUVVaNk9HMGxNa1pVVW5CUmVYcHRNMlpZTWpkQlVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW5hVzF3TG05eVp5VXlabkIxWWlVeVptZHBiWEFsTW1aMk1pNDRKVEptZDJsdVpHOTNjeVV5Wm1kcGJYQXRNaTQ0TGpFMkxYTmxkSFZ3TFRRdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UjBsTlVDMHhNekl4T1Mxa2NDNWxlR1U9

http://www.bundleflashapps.com/WVl6OTRQV0kwZDNsT01ISTFKVEpHUkZKUE9VWkhNbVZwVEU5aFoyd3laWFJoVDB4TGJtcHdkVUp4V25sdFJrVmtOQ1V6UkNaalBXOVNaRWgxU2xWRGJXTmhkVFZaYldsUU9HeGlkSGgxV25WRk1EZHpSR1pMZUdSNGFXMWlZak52UTI5VVpERnpaWEZKVEhaalVuUlhNMU5SWW5GNWVXaEVha2s1UzBwNUpUSkNkM1pLTVZaRlVWZFNOM2s0UzNwUGNqQTVkSEJwT0VWR1NraHRObWRGTjNCWFJuVWxNa0pJUkhWU1FtSjZhR2hyVUZkRlFXd3pKVEpHTTNsTmREa3pUV1pXZGxKUlMwaHNTRE5hYzBWRFRFaFVVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVprYjNkdWJHOWhaQzVuYVcxd0xtOXlaeVV5Wm5CMVlpVXlabWRwYlhBbE1tWjJNaTQ0SlRKbWQybHVaRzkzY3lVeVptZHBiWEF0TWk0NExqRTJMWE5sZEhWd0xUUXVaWGhsSm1SdmQyNXNiMkZrUVhNOVIwbE5VQzB4TXpJeE9TMWtjQzVsZUdVPQ==

http://www.stockbundlecentral.com/WVl6OTRQVkoyY1Vaa01ubzBSWGQyU0RWamJVSk9jVEF5YVZocmRtUXpTRlJoV1cxQmJ6STBOelYyVjNkeVMxRWxNMFFtWXowMUpUSkdOMmhtU2s5SFR6VnFSU1V5UW5OQlJXVkhPRTFXUjNCcGRuWklPV2RpZDJGNmREUjRkV1pZWVZWWlVsQjFTbTVVT0hCNGNFNXNjVzlOYTFaM1puUktkRnB6ZDFKV1p6UnpaRkpFZHlVeVJrODBVWEJaTTJscU9YTXlaMEpQSlRKQ04xWlNPV1JQUkhWaE0yeFBaMHBtTXlVeVJqWm5TRzE2VEU5dFJHY2xNa1pHUkhOc00xZGFVRTluUnpoM1FqbG5abFpVU205SVV6aDFOMDlUV21jbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdVoybHRjQzV2Y21jbE1tWndkV0lsTW1abmFXMXdKVEptZGpJdU9DVXlabmRwYm1SdmQzTWxNbVpuYVcxd0xUSXVPQzR4TmkxelpYUjFjQzAwTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVWRKVFZBdE1UTXlNVGt0WkhBdVpYaGw=

http://www.grabappsdownloads.com/WVl6OTRQVFpuWTNSRVFrcGFUbFJ2Y0RWbmVURkZaV3hWZDI1SmNtcFNUREpEVjBoc2VUVk9jM0ZrWlZOc2FHTWxNMFFtWXoxbU1YQlJUV3R5YUROM1F6Vm9hRFZhWWtvM1JHWmlNR2h0TTBKSlRuZDJhV2htU1RCa1EyVllKVEpHVmxJM2RIWklZMnQxWW1oTllWRkhKVEpDU1ZSSlRFNU9ZbmhXVERocVQzSTJiMnBISlRKR056UWxNa1pUUTBkNlJTVXlSbFpVZVVoVVExcHZRaVV5UW1aMU1uSkVZMnQxUjBzNFQzaFZjbFJ1U0hwbmVXRnhaa0prU0ZsT2VuVm9VREZ5TXpKTVkzaDZSSFo0Y21sblpFVnFZbVZaYWxFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdVoybHRjQzV2Y21jbE1tWndkV0lsTW1abmFXMXdKVEptZGpJdU9DVXlabmRwYm1SdmQzTWxNbVpuYVcxd0xUSXVPQzR4TmkxelpYUjFjQzAwTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVWRKVFZBdE1UTXlNVGt0WkhBdVpYaGw=

http://www.clearuniversecapital.com/WVl6OTRQVkZNU1c1aFJsVjBVVUZMVVdoUFJYSmFTM05CU0VrelNtSm5RamxoVG1JemVHeFBkbnBNYmlVeVFrbE5PQ1V6UkNaalBXUk9aa3N3U0VkdlJGTmhZbGhhYVVaMGJWbzNiRkJ3WTNKdFJVMW9VekZLWW1wbVNuZDZZbkJsVVZCbFJGVnFkRUZuY2lVeVJqRkpSakVsTWtKWlprbHdhRlZJTldveVUyVnBWMFYyV1hwR2MxWTNORmhRZVRoMlJ5VXlSa2xhYmxGSGVFWmpNbWxRU1VkdmEzbFhZakZIVUU1aVZqTTFTVkpwYW10c2JVbFRZMkZxVUdWclpuVkxVemxKU1d0Sk5TVXlRbkY2TVd0M1kycE5URlIzSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG1kcGJYQXViM0puSlRKbWNIVmlKVEptWjJsdGNDVXlabll5TGpnbE1tWjNhVzVrYjNkekpUSm1aMmx0Y0MweUxqZ3VNVFl0YzJWMGRYQXROQzVsZUdVbVpHOTNibXh2WVdSQmN6MUhTVTFRTFRFek1qRTVMV1J3TG1WNFpRPT0=

http://www.stockbundlecentral.com/WVl6OTRQVWtsTWtJeU1EZHphbmxPUlZCNWRYSlJPR2N6VlZGRFRYZ3lZamh6V0RkVGMwTjNkRTl1YTFaQ09HNTNNQ1V6UkNaalBUZ2xNa0o1TnpoUk5qSlJiMGsxU1RKM1owaFVRblUzTURWV05VWnFPVVpYTWtJMVVFWlpUVkV4VmtsT2JHbDNZMEZKTWxoV05EZFlVaVV5UWxKb1RreFFkR05pTVVGck4yMVRaQ1V5UWpZelJIZDBTemxIWTA0d2VGWWxNa1pHUW5aR01VVTRKVEpDV0cxaWFWWk9NREZQZUZJMEpUSkdUMnd6UlZKT1EycEhRalpaUW5KalNFOUZZM2g2VUdSUVJERkdSVFJqT0ZkM1RtWTNURlJQTURkSlVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW5hVzF3TG05eVp5VXlabkIxWWlVeVptZHBiWEFsTW1aMk1pNDRKVEptZDJsdVpHOTNjeVV5Wm1kcGJYQXRNaTQ0TGpFMkxYTmxkSFZ3TFRRdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UjBsTlVDMHhNekl4T1Mxa2NDNWxlR1U9

http://www.headcycleuniverse.com/WVl6OTRQWFlsTWtaWFExTXdPV0ZQWWtoS05UazRhVGxEU0VFMVRVZEVkbG96VEZZek0ySnNhVmR2YWtocVkwUnFVU1V6UkNaalBYWnNiMFp6Y2pGVlpuVjRSbXQ0T1d0bmRHOXhRVGMzTTAweEpUSkNKVEpHZDI5WGFUSmtWRXh6WkdwMFNscHpSMEZOVFcxSmVuZEJUa0ZQZUVKbWQweHdjRmRTSlRKQ2NsbHBZWFExVGs5amVVUldhMEZwZDFSaFdtd2xNa1p6SlRKQ1lpVXlRblFsTWtKQ1lUQjNUa0ZTYWpoRVNYb2xNa0pLVUVGR1JsVlNTaVV5Um1OWVptbEhOMjVZTVd0bU9GQmxjaVV5UmpsU1oyWnhlalpyUWpseE5qVTFkMFEwYzNGbkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVptUnZkMjVzYjJGa0xtZHBiWEF1YjNKbkpUSm1jSFZpSlRKbVoybHRjQ1V5Wm5ZeUxqZ2xNbVozYVc1a2IzZHpKVEptWjJsdGNDMHlMamd1TVRZdGMyVjBkWEF0TkM1bGVHVW1aRzkzYm14dllXUkJjejFIU1UxUUxURXpNakU1TFdSd0xtVjRaUT09

http://www.headcycleuniverse.com/WVl6OTRQVzloUVd0MVJYSlhka00yZFRVMFJUWkdPRVp6TTFoSFpWWTFXblVsTWtaYVMydFFPRWhxY0dOTFpIcEdaeVV6UkNaalBTVXlSa1E1YmxKeloxbEtZbFY1V0VKaVZ6VklWemw2U201VmVYRlljakp3U0ZJbE1rSnFjbEpETjJ3MmNWRXlZbmxrTlVobU1HRkVUWGxST1hNMFZuRjJZVmhyVnpnMlUyTnZWMHRLV2xOc1ozQnhUMnd5ZWxkR2QxY2xNa0pMYzB4a0pUSkdSamwyYkhOdE9EaDJWM3A1UkZRNE16Tk1aVWx3VEc4MVNYVlhKVEpHV2lVeVFtbE5iMHhYZGtzNE5YcFBja1V6YUZnMU5URTFWR2RvVjFsV1p5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW5hVzF3TG05eVp5VXlabkIxWWlVeVptZHBiWEFsTW1aMk1pNDRKVEptZDJsdVpHOTNjeVV5Wm1kcGJYQXRNaTQ0TGpFMkxYTmxkSFZ3TFRRdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UjBsTlVDMHhNekl4T1Mxa2NDNWxlR1U9

http://www.todaymetabundle.com/WVl6OTRQVXRyY0hocFpWTmthRWN5U1ZwT1RtOUlhRGh3YkVRemNHVmpXRzB4VkdZemRsSnZVR0pzUlVGelMyTWxNMFFtWXoxMWEzTmFORUpMUmxselJqQnBibVJYUzBab1FWQTVVVXBsY0ZKWFJGRmxPWFZZWjNGSWJITTJiRlpzUVVwVFRFcGhlVWRTTjBsNmVHMXhSbXB0UmtWTmEzZG9OU1V5UW1sVVlucG5VVFpoVkVwc1JUSmtWbFZtZENVeVFtTnJhekZNT1RGRlYwdE5hazF3TnlVeVFrWk5RU1V5UW5semFYVlFjWEZwU1haS2NYSkhSR3RtYjFsRlYyb2xNa0lsTWtKd2MxQWxNa1p1U2xaR2JUUmlTWE5LZVU5UVVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW5hVzF3TG05eVp5VXlabkIxWWlVeVptZHBiWEFsTW1aMk1pNDRKVEptZDJsdVpHOTNjeVV5Wm1kcGJYQXRNaTQ0TGpFMkxYTmxkSFZ3TFRRdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UjBsTlVDMHhNekl4T1Mxa2NDNWxlR1U9

http://www.bundleflashapps.com/WVl6OTRQVmxVZVhwS1VERTFlSE0yZURkMmRqRnBjRnBXWjFKSlprOVhkek5YT1RWd0pUSkNSRVZXYUhwSFNscEtieVV6UkNaalBUVTNKVEpDUVhBNU5UQlplVmRrY25wb1oxb2xNa1o2ZG5aTU5XMUtObWxuTlVkcGVHSlFOVVEzYTFKT2IzaDNKVEpDWXpaWWVEZFRaVXBoSlRKQ1ZVY3daVmhSZEZscVJ6Y3dlbFpvVTI1UmJGSnBiVEpxWkV0aU5UTkJNWGR3WmxKNFkxTnFhelJsVkdoSFdHcEVkRXRrTm01T2FqWlZXazVGZVRoSFdESnhUalp6V0hKa1IybzVRM0VsTWtaM1pXZFllVk5XUmxGSFMwTllRa1phTlhjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdVoybHRjQzV2Y21jbE1tWndkV0lsTW1abmFXMXdKVEptZGpJdU9DVXlabmRwYm1SdmQzTWxNbVpuYVcxd0xUSXVPQzR4TmkxelpYUjFjQzAwTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVWRKVFZBdE1UTXlNVGt0WkhBdVpYaGw=

http://www.stockbundlecentral.com/WVl6OTRQVzAxVDJneFZtOW9aekZXZDBKc1pqaGxOWE5yTlRBMlNGSnpWRnBZWkZOV01qUk9WbGh1YUdsTlNEUWxNMFFtWXoxcVdHczNURmhETnpkVFZ6TjNRbVJ6ZGxCWEpUSkdjalZvVkZKTFkzUmFNVzFCVjBjeFdVTjNKVEpHVEdKSmJ6Qk9hMk41UzFKTmJIUnNla1JNV0Rsc1VITjJVblpqVlhkRVkwcE9lVzk0TURFMGNEWXlhRWx2TmxCbWJYWkNUbThsTWtKallYQjFNV2hKWlcweVJqTjVNRm9sTWtaVlVVRjJabkkzUVZWUUpUSkNNVGh6YUZWUU1ITmphbGRFYjFGT2EyeEVPVFJrWjFOMmFXTmFNa3BuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG1kcGJYQXViM0puSlRKbWNIVmlKVEptWjJsdGNDVXlabll5TGpnbE1tWjNhVzVrYjNkekpUSm1aMmx0Y0MweUxqZ3VNVFl0YzJWMGRYQXROQzVsZUdVbVpHOTNibXh2WVdSQmN6MUhTVTFRTFRFek1qRTVMV1J3TG1WNFpRPT0=

Latest 30 of 46 download URLs