acdsee-video-studio-58840-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application acdsee-video-studio-58840-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
672ba4fdf5813b7907584e4dfbebf0f2

SHA-1:
924340ad7568cde444b8c6fbffad31f325da8041

SHA-256:
012fed7caf73699e73ab2a95d454d8d2974101dd4fa27bc912f4620447874763

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 8:27:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.10

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\acdsee-video-studio-58840-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:tCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:trrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file acdsee-video-studio-58840-dp.exe has been seen being distributed by the following 36 URLs.

http://www.bundleflashapps.com/WVl6OTRQVE5XUlV4NUpUSkdVRVZaWlVGSlJHUTFKVEpHUmlVeVFrSjNkWGhZYVc1eFJHNUdSbVY1VTJKc00wYzNSVkJ5TnpnbE0wUW1ZejF0VjNSSlMxVnJZekp2TlV0S0pUSkdiVTFHYkdWVlYxQTRkM3ByU0haaVYwOVFjRGhMYzFWb1QwNVRTamg0VVd4U05GUXhWRzE1VDBSdVFtODBZbXQzY201SFdtTjNOVEl4YjFGa2JWSlBVVUYzTUd4R01WWlJhakpwTWlVeVJtWkJObEp3VmtSQ1lqWnhVV1ZQWmpSRGRHZG5KVEpDU0U1Vk9ITjVRakpLVTJwU1ZtRjVPVGROWjNGdk1uQXhSalZFYlNVeVFrNTZObGM1UVhSMVp5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiQzVoWTJSemVYTjBaVzF6TG1OdmJTVXlabUZqWkhObFpTMTJhV1JsYnkxemRIVmthVzhsTW1abGJpVXlabUZqWkhObFpTMTJhV1JsYnkxemRIVmthVzh1WlhobEptUnZkMjVzYjJGa1FYTTlRVU5FVTJWbExWWnBaR1Z2TFZOMGRXUnBieTAxT0RnME1DMWtjQzVsZUdVPQ==

http://www.todaymetabundle.com/WVl6OTRQVlpuTmxadE1uSklObFZ5UVNVeVFubEZUMVY2VDJsQ1NGVm5iMDFWTms1cWNWUnRlRWR0VHpWU2VHeHdkeVV6UkNaalBVRTJkbkE1TUROYU9VVXdaelJVTUdKaGFtMUdiMjluVHpKbVFXSXpOVTFqWkZwNmIxQllTbkJDWlZOcVFYZ3dlazlPTmxveE5reGljMjEyVWsxV2JVSkxaa2cwYjNKbldFUlhTVk5uZG1WdVFWTTVTaVV5UW1kd1VtTTFZVE55U2lVeVJqRTRhV2hwYWs1WlJuSnFkM3ByYW1GMWRrcG1VSFl3Tkd0R1kwdHBXVGcwT1RBM2JWVjNlRVpUYmtSblJHRndVVlZCYVRnMFpXY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1aR3d1WVdOa2MzbHpkR1Z0Y3k1amIyMGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2SlRKbVpXNGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZEUkZObFpTMVdhV1JsYnkxVGRIVmthVzh0TlRnNE5EQXRaSEF1WlhobA==

http://www.headcycleuniverse.com/WVl6OTRQVmQyUjFkU1JqSm1VVkk1WlNVeVJrSllOMVJRYnpVbE1rWm9lVmRUZFUxTWNqSk9Ra056V1hKNE0xQTBWa2gzSlRORUptTTlZMUpPWWs1RVprNUJNVkY1VEVOU1ZtWmpSVU5SWW5NNWJ6Wm9VRzQ0YkVkMk5scFZNVkYxTkVSVlREZGtla3R0VVdwak1qSk5XVlYzWkVVbE1rSXhPVWdsTWtKeVVWVndjVXh1TlNVeVFuVjBkakpzV0RrM1ptVmliRmh6Tm5OMmFYaG1XWE0xTm1VbE1rSmFOblZsUlhScWVuQk1WMnBXWkZWTlpIcEZjVkVsTWtKd2FuSkdjRlprY2xGQ1JHMVNaMmR2WkV0U1V6UWxNa0o0TkhrMFNqQkJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVJzTG1GalpITjVjM1JsYlhNdVkyOXRKVEptWVdOa2MyVmxMWFpwWkdWdkxYTjBkV1JwYnlVeVptVnVKVEptWVdOa2MyVmxMWFpwWkdWdkxYTjBkV1JwYnk1bGVHVW1aRzkzYm14dllXUkJjejFCUTBSVFpXVXRWbWxrWlc4dFUzUjFaR2x2TFRVNE9EUXdMV1J3TG1WNFpRPT0=

http://www.grabappsdownloads.com/WVl6OTRQVVpLVFVoYUpUSkdKVEpHVkZoak1GVmthV1I0YTNScllVTjNVblZqTkhadmJHdHliM0pNV2tKUE1sRkdibkJCSlRORUptTTljaVV5UW1wNmNESmtaV1ZHUkhKb1RFUlRVRU1sTWtKeVQyaG5SbTlaUzJKR01YQTNiak5QV1ZjMWJHMUlZemh2TlZsSVUwUmlaV2tsTWtaUk1VeHlWM2RGYURSVFFsaDFabUZ2UVdWa1NEUnVkM3BHWnpWb1dVUXlWek5LWVVvMlNYQlpkVkV5ZG14c09HdEVWbEZXVW5GNE5rbFBVWEV4TXpkWVNFVlRRMjlpT1ZFMGFVNXZTRGRLTW1oWlZFbFRabVk0UlRWUVVYY3lXbFZCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1Sc0xtRmpaSE41YzNSbGJYTXVZMjl0SlRKbVlXTmtjMlZsTFhacFpHVnZMWE4wZFdScGJ5VXlabVZ1SlRKbVlXTmtjMlZsTFhacFpHVnZMWE4wZFdScGJ5NWxlR1VtWkc5M2JteHZZV1JCY3oxQlEwUlRaV1V0Vm1sa1pXOHRVM1IxWkdsdkxUVTRPRFF3TFdSd0xtVjRaUT09

http://www.bundleflashapps.com/WVl6OTRQWFI2WkZOTmFYVm1XVlpXYUU1emNYRnlNMDVQWTNvM1ZFMWhaVmtsTWtKalFtWlNTVGhMUWpoaVJteFJVU1V6UkNaalBUZHJTMDVaYjJNM01FeDZOSEZHYldGUVRVSllTM2hhUVRrNVYzaFFkVm93VkhoaGVsTmlhMVVsTWtZeldVWnpiR3RpTlcxSmFtbFJkQ1V5UW1kTE4xSm1ORWhSZWtOaFpHNGxNa1pFTTA1M1VXOUhlR3g1ZWtGeWFXOXhPRkIwWldOb1oweFVaRU5NVUhkclNqUkxjMHBNZFhVd2FIQm9VWEJRV1dSWlEwcE5aM1Z1VmpSSU1VbDBPVkZDTlZSdFVWcFRjM0ZZUTFoWGEwdFFaeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVprYkM1aFkyUnplWE4wWlcxekxtTnZiU1V5Wm1GalpITmxaUzEyYVdSbGJ5MXpkSFZrYVc4bE1tWmxiaVV5Wm1GalpITmxaUzEyYVdSbGJ5MXpkSFZrYVc4dVpYaGxKbVJ2ZDI1c2IyRmtRWE05UVVORVUyVmxMVlpwWkdWdkxWTjBkV1JwYnkwMU9EZzBNQzFrY0M1bGVHVT0=

http://www.todaymetabundle.com/WVl6OTRQWE5QWm1KV1RYSWxNa1pOVkVGVlFUSXlhalJ5UlVKcU0xbE1VbFZSTlVKVVJsSktOMHhGYzJsdlZVSnBSU1V6UkNaalBYUXlaVkpzWVZoMFZHdzVKVEpDUm5wd01FdDBKVEpHVHpCUFEySmhPRGs0ZVc1SFUxWXlZVkJzVUd0b1RUTkpXU1V5UWs4elYzaFNjbkZVWmtsSWIwRndlR3RrYzNCSGFqaFJOVFJYUzNORmRFaGxTbEp3Ykd0QmFqRnRlbGRDUlhoSFdHOUhKVEpHTVZsWVVFVldXRFJUVUdSbmJtWkdVRFJ2U0VaUWNXWTRTM2N5ZFhkVmNXMWlabVp6TkdseVZtcHhPR0lsTWtaTE5GQlNkRmh2TUhjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHd3VZV05rYzNsemRHVnRjeTVqYjIwbE1tWmhZMlJ6WldVdGRtbGtaVzh0YzNSMVpHbHZKVEptWlc0bE1tWmhZMlJ6WldVdGRtbGtaVzh0YzNSMVpHbHZMbVY0WlNaa2IzZHViRzloWkVGelBVRkRSRk5sWlMxV2FXUmxieTFUZEhWa2FXOHROVGc0TkRBdFpIQXVaWGhs

http://www.tagtowerscapital.com/WVl6OTRQVEEwWmpsaFdrUjRjbXAxWlU1UU9XdzBkbVpPV1UxQ1lWbGtjRzUyYmxFNE0yMVpUa3M0TUdoRk1WRWxNMFFtWXoxaVVuTjZKVEpDUzNaa01TVXlRbGs0TW1VNWJteHNVa2RIYnpoeWJ6bFVia3htYUZSTlRXaHBWa3QxYjBSRmQwcDBaRXhJVEZZNFRHRnBhRkJTTVRoQlJURkNSREpGWkdFME1saEhRMU5KZGxsQ1VXdDVNVmhJZGtSeFFVZzRPU1V5UWtSM1RtbFBORkpaU20xWFYzZE5ZVkZHVEZGYVExbEZWV0pZYWxsbFpFZHRabk5CZEdsaU0yUXdNM1JoUkRGQmNWVmlabTVaWnpOd1RVRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1aR3d1WVdOa2MzbHpkR1Z0Y3k1amIyMGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2SlRKbVpXNGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZEUkZObFpTMVdhV1JsYnkxVGRIVmthVzh0TlRnNE5EQXRaSEF1WlhobA==

http://www.contentdownloadmega.com/WVl6OTRQVEl4VFRsTlZqYzRibnB6WVVWaFJqSkNZalE1VGlVeVJuUmpSRTUzVVVGMkpUSkNaaVV5Um1OVGJUSkRNaVV5Um5OMlFTVXpSQ1pqUFdRME0xUlNTM1pNVmpkU1ZXTnBkWEZZYUVOUmExWm1UVkpUYW10amNqRXlaMkl5VDFSVmFDVXlSa05rUVRkQ1JHZHFUMnB2ZFZKVWVtRmpkMVUwV1hWTGQzRTBlVFpDUjNSb1NUaGlSRXAwTUU1eVdXeE5OR1JSVjJ4dWJDVXlSbEYxVVRNMmMwTjFibll5VW5nbE1rWllSRlpNZUhCdVF5VXlRazhsTWtaU1MwNWlSRzB6ZVVKYU0yMXJVVkJrY0dGcGJFeFNVR2swVkdKT2JEUndSMEVsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptWkd3dVlXTmtjM2x6ZEdWdGN5NWpiMjBsTW1aaFkyUnpaV1V0ZG1sa1pXOHRjM1IxWkdsdkpUSm1aVzRsTW1aaFkyUnpaV1V0ZG1sa1pXOHRjM1IxWkdsdkxtVjRaU1prYjNkdWJHOWhaRUZ6UFVGRFJGTmxaUzFXYVdSbGJ5MVRkSFZrYVc4dE5UZzROREF0WkhBdVpYaGw=

http://www.grabappsdownloads.com/WVl6OTRQV1pOWWxjMWNFWk1WVGhwWlRRNVVHZDRNVEJZV25aR2FHTnNVMmxoZUdWWVRsTnRhMVV6ZEc1M1VITWxNMFFtWXowNE5WTmlaVVZFWmtWQk1VNVVla2hPTlhCTVpVdHhUMWxSYVdOSmIxaGFUVVZsVVZaaVIzbGlTM0l6VTI5MU5UQTFZMmRNT1VjemEwRkplREF3V1ZWNFZGUjVWblV5UjFJMVNXOW9ObGt5VEVOeWEwTmhSVkJYUkdWbVIzcFZOMndsTWtKWGR6aDBUM0l6ZFhGcGFFRlJVbVpUZDBVMk1VcFlUbGd6T0ZaWkpUSkdiM1pxTldOMWFsRm1PWG9sTWtKeU0yaENXRkpvZUhkeVduY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1aR3d1WVdOa2MzbHpkR1Z0Y3k1amIyMGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2SlRKbVpXNGxNbVpoWTJSelpXVXRkbWxrWlc4dGMzUjFaR2x2TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZEUkZObFpTMVdhV1JsYnkxVGRIVmthVzh0TlRnNE5EQXRaSEF1WlhobA==

Latest 30 of 36 download URLs

Remove acdsee-video-studio-58840-dp.exe - Powered by Reason Core Security