ares-12480-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application ares-12480-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
d3277445a0e161d73948f65dd1909a50

SHA-1:
9e323a2ddaf2f76df13ad8b2524d715d70bc3520

SHA-256:
697770c20f3abcf2fbd717f268aa061e45a475e805ce97b2aea7972943370718

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 5:30:27 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.10.0

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\ares-12480-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ZCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:ZrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file ares-12480-dp.exe has been seen being distributed by the following 50 URLs.

http://www.todaymetabundle.com/WVl6OTRQWFEzUVdscmIzRnNiMEZaY3pOVWVHcDVSSFpPUW01RmJtODNNbk5zU1hkVFptczNkbXBCUVVsS2JYY2xNMFFtWXoxeFNHRlliV2N5VVcxUlMzWXdNMFZKVEVKVmFGQjVaRFpsWW5CQ2REZGFWblZ1WldkUGNEWTRkazUwUzJsT1dqVjRZM0E1Y0VVelExTTVSMGcyYkdwbEpUSkdTMXAzVlc5VVQxZGpKVEpDTkdaNEpUSkdKVEpDY2xSNFRIRk9ha0ptUmpGd1EwSlhVWEZ3ZWtoUWNVVlRkbGN5VDA5SWJuQWxNa0pLZUc5SlZuYzBUa05GTjI5SmFIVjZaREZ0V1VzeFUzZGlXV0U0U1VoalJucHJiV1ZCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm01bGRHTnZiRzluYm1VdVpHd3VjMjkxY21ObFptOXlaMlV1Ym1WMEpUSm1jSEp2YW1WamRDVXlabUZ5WlhObllXeGhlSGtsTW1aaGNtVnpaMkZzWVhoNUpUSm1RWEpsYzFKbFozVnNZWEl5TkRGZk1EVXlOREUySlRKbVlYSmxjM0psWjNWc1lYSXlOREZmYVc1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZ5WlhNdE1USTBPREF0WkhBdVpYaGw=

http://www.funsignssend.com/WVl6OTRQVUo1YUZWV2EwUlJVMk40Y1NVeVJubFhNM0l5SlRKR2JEVlNjakJHSlRKR1JtdHJjRTlFTW5wYU1XVjRkR3hJYUdjbE0wUW1ZejFhVmtGT2VHVnVlVkpLTTJoWU4wNVBhbkZaT1ROV2NUUWxNa0pvYzNad05UVlpRbEpKVFZwMlFXMTJWVTFPVTBacFJXZEdTMFlsTWtaWGFHazBWU1V5UWxodVVXZHFlbEYxZDBVd1FtTmFPVTlvZUdKdWNtTlhkVUpuTlVKTlVEZGFNV1I1SlRKQ2JuSnpVazhsTWtaM1QwSjRTazh6SlRKQ0pUSkNNVEJxUVZkU2RsQmFZbGw0VjNoTFpESnpkalIxUkVsbE4yaFlXRXMyVWtGSGFXUmhNeVV5UWs5M0pUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVptNWxkR052Ykc5bmJtVXVaR3d1YzI5MWNtTmxabTl5WjJVdWJtVjBKVEptY0hKdmFtVmpkQ1V5Wm1GeVpYTm5ZV3hoZUhrbE1tWmhjbVZ6WjJGc1lYaDVKVEptUVhKbGMxSmxaM1ZzWVhJeU5ERmZNRFV5TkRFMkpUSm1ZWEpsYzNKbFozVnNZWEl5TkRGZmFXNXpkR0ZzYkdWeUxtVjRaU1prYjNkdWJHOWhaRUZ6UFVGeVpYTXRNVEkwT0RBdFpIQXVaWGhs

http://www.clearuniversecapital.com/WVl6OTRQVVpDV1dOWlUyeENUSFo2Y1doTE5YSnBjREo2VTJZbE1rWTRWekUyVlc1WGEyZFpUbk5YY1RJbE1rSjZOVkZ2SlRORUptTTlSbEp0VURGQ0pUSkdNR3BoTVhaVFNrSmxXamRRYkVOYU9XVjRWSFZvZFNVeVJrZzFPVFp3VWpsTVZuTkpTWGxaZEc1amRtRk1NbGwyTlRoUU1EaHFPWEZEUlU0bE1rWXhaMVppTlVSMGFXbExVa3N3TVdsaEpUSkdKVEpDY0U5R1ZYTTFkbUl5VWtWSVQzaDFTbVZMVjBSRVR6ZENUVGx1WkVwRVpuQnBjbXBFZFVkUVpXdGFiSG8zZVRGVFMzazJXSFZWTkVad1YwRTNkV2QwVURaVFVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnVaWFJqYjJ4dloyNWxMbVJzTG5OdmRYSmpaV1p2Y21kbExtNWxkQ1V5Wm5CeWIycGxZM1FsTW1aaGNtVnpaMkZzWVhoNUpUSm1ZWEpsYzJkaGJHRjRlU1V5WmtGeVpYTlNaV2QxYkdGeU1qUXhYekExTWpReE5pVXlabUZ5WlhOeVpXZDFiR0Z5TWpReFgybHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxQmNtVnpMVEV5TkRnd0xXUndMbVY0WlE9PQ==

http://www.tagtowerscapital.com/WVl6OTRQWEJYY0ZaeFZUUXpkeVV5UWpKcGRGSjBTalJLWWxSd2NYRkZOMnBTTkZweVVYTjRZeVV5UWpNNVVtdHhNWFp2SlRORUptTTlVemh5Y25KRE1VdzRPSGs1VFhCWlZHaHRSbmhFUjFaRlVVNDVWakZIU1dGaldXdFFRa3AzWm1ScWREZEtZMWxKYURaYVVtVldOVFY2SlRKR1FsQlFOa2g2Y1NVeVJtbFFRa1pzY2pBMmFtUjVNVWxRSlRKQ09HOXFWV3M0V0V3M01GcEZVbVZhWmxsd1VGaHBjQ1V5UWlVeVJuTndlaVV5UWpScU0zSjJZbGxRTjJwa1prSmpaREE1VGpKb2FqTXljV3d5T0RsSmFXOVljREpxTkhCblZWUm5KVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabTVsZEdOdmJHOW5ibVV1Wkd3dWMyOTFjbU5sWm05eVoyVXVibVYwSlRKbWNISnZhbVZqZENVeVptRnlaWE5uWVd4aGVIa2xNbVpoY21WeloyRnNZWGg1SlRKbVFYSmxjMUpsWjNWc1lYSXlOREZmTURVeU5ERTJKVEptWVhKbGMzSmxaM1ZzWVhJeU5ERmZhVzV6ZEdGc2JHVnlMbVY0WlNaa2IzZHViRzloWkVGelBVRnlaWE10TVRJME9EQXRaSEF1WlhobA==

http://www.funsignssend.com/WVl6OTRQVFpDSlRKQ1ZGY2xNa1pTSlRKR2JqTnpVME5SSlRKQ1VFMW9ZbWhxZDB0UFlXWXplV05ZVHpoMWNVdExkMFl3YTA4d2F5VXpSQ1pqUFVOWk0wWTFUWGdsTWtKdWVrazNPVUphY0dKWllqSnZWMlpqUzBWSU5uWmtaWGRHVjIwbE1rWjNXVUk1V0VZd1pHZFFaVUZOUmlVeVJqUk9iQ1V5UW1aWlduWkpkbGx2WWpCamJtcHRRVGhtYjFRME4yaE9SM0ZxUTJsTGFsaE5XV1puWm0xQk9EZExlSFpsV1hsb2JtcFJTSE5HTXpSaVlVSlFkVk01VHpGYVJqRlpVa3d5Y0hSb2N6Y2xNa0l4TlRaeVF6bHVKVEpHYlRWdlkzcFJPRUZQWnlVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1adVpYUmpiMnh2WjI1bExtUnNMbk52ZFhKalpXWnZjbWRsTG01bGRDVXlabkJ5YjJwbFkzUWxNbVpoY21WeloyRnNZWGg1SlRKbVlYSmxjMmRoYkdGNGVTVXlaa0Z5WlhOU1pXZDFiR0Z5TWpReFh6QTFNalF4TmlVeVptRnlaWE55WldkMWJHRnlNalF4WDJsdWMzUmhiR3hsY2k1bGVHVW1aRzkzYm14dllXUkJjejFCY21WekxURXlORGd3TFdSd0xtVjRaUT09

http://www.contentdownloadmega.com/WVl6OTRQWElsTWtaTmJXYzBlV04xTmpreU9HTnZObEpKWVZGNVdYRnRkbnBOVDI0emIyOTFVMnhDWkRBek5tWTFOQ1V6UkNaalBWbHlRM3AzUjNKelNXUnhWREJPTlhsT05VMXdVbWs0UVdaUWRuQmtReVV5UW14VE1rRnlWVXhuZFVwUU4zQlpabWwxYVVSNk5YVkZNVVYyUjNReFlrTkdNM3BIWW10dVQwd2xNa1l3UmxKVU16TnZjRGQzUkVzeFNUbDJKVEpHYzFKUFRtdEtlVGhKVW05d2JqY2xNa0k1WTJRM2NtMHdTa3RxVGtNd2JtbHNUWFp0VEU1c1dHOWFOblpFUWt3eVdFWnJUVlkyTVVjMmExRm9SMkozSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm01bGRHTnZiRzluYm1VdVpHd3VjMjkxY21ObFptOXlaMlV1Ym1WMEpUSm1jSEp2YW1WamRDVXlabUZ5WlhObllXeGhlSGtsTW1aaGNtVnpaMkZzWVhoNUpUSm1RWEpsYzFKbFozVnNZWEl5TkRGZk1EVXlOREUySlRKbVlYSmxjM0psWjNWc1lYSXlOREZmYVc1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZ5WlhNdE1USTBPREF0WkhBdVpYaGw=

http://www.worlddlstock.com/c?x=UZu2YGdAKYSn2vB/994iSI91xG3lOcEmTLv/Rek78SQ=&c=hbat M0QbNks682WeHZTh8Yh 52inV aF/DLkxjneWxdPb8QS8kR0PUaXbvkzCVDIQQE1XznDnMJpv8kUEmoZyb3BwUBXGOFTPlPBdFGlxNbVoUgy7bAT0g4qxvXdccHnZHU3texbcXw3XsHxNDfPYWbR49yL8mtyFwU9nvEpKU=&e=0&fallback_url=http://netcologne.dl.sourceforge.net/project/aresgalaxy/aresgalaxy/.../aresregular241_installer.exe&downloadAs=Ares-12480-dp.exe

http://www.tagtowerscapital.com/WVl6OTRQVGNsTWtKbE5XUXlSV3hzYkdJbE1rWkZPRUZtZGtKbVZYQnRNMEZMV1hoblV6ZGxlVlkxWVdKc01VMVpWbU5ySlRORUptTTlSbEEyT0ROT1JpVXlSa0pxSlRKQ1RscHJlV3RUYkdZMWJVSnFNWGxXTW1adGFGTklTR1IwUlhvMWVVTkJKVEpDZEhGdE0yNTVPWGx5U2pjeldHRlJSVkJRUVZkVE1uSjBXSFZrYjB0blZreEpPRU14TVdoUFExRXphbkl4U1RaWE1uTlpXbFp1WVU5a1ZWa3lVV1F3UkZWNU9IVjJSell4TW1sd1lsSklSWGhNVFdnemFXaFNaVGgwYjBzNVZrRnVWMVoxZFRaamVsQkxWVUpuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm01bGRHTnZiRzluYm1VdVpHd3VjMjkxY21ObFptOXlaMlV1Ym1WMEpUSm1jSEp2YW1WamRDVXlabUZ5WlhObllXeGhlSGtsTW1aaGNtVnpaMkZzWVhoNUpUSm1RWEpsYzFKbFozVnNZWEl5TkRGZk1EVXlOREUySlRKbVlYSmxjM0psWjNWc1lYSXlOREZmYVc1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVUZ5WlhNdE1USTBPREF0WkhBdVpYaGw=

http://www.bundleflashapps.com/WVl6OTRQVTlKYVhBeWVWTkxOMHRwYUZGV1EyWWxNa0pSTWt4S01reFRVbTlOYVRCM1VEUkNZalZGZDFwdllWZzVUU1V6UkNaalBWTnZhVFo2VURWSlJFWlJaRTltVDBwa2NqVTNjVXhZTUROS1Iya2xNa0oxZDAwM09YYzBTMHhDUTI5aWNGTXdRMEZRSlRKR1QwaERSV3h3UVVGWE0yNTBaVzlNYURsc1NXSk1URFJyWlVoNmFVSjVVU1V5UmtWeEpUSkNhRlpyVVdOeGJsUkRia1EyYVZsck9VSkdZbmxxYUZGU1dFUmFSeVV5Um5oVFNGQk9lRmRDVkdVMlJsWXhTalI2ZEVWeVVFNUxjSE5xZEc5WVlYRTVkVmwwSlRKR1VTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnVaWFJqYjJ4dloyNWxMbVJzTG5OdmRYSmpaV1p2Y21kbExtNWxkQ1V5Wm5CeWIycGxZM1FsTW1aaGNtVnpaMkZzWVhoNUpUSm1ZWEpsYzJkaGJHRjRlU1V5WmtGeVpYTlNaV2QxYkdGeU1qUXhYekExTWpReE5pVXlabUZ5WlhOeVpXZDFiR0Z5TWpReFgybHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxQmNtVnpMVEV5TkRnd0xXUndMbVY0WlE9PQ==

http://www.bundleflashapps.com/WVl6OTRQV2hQUzFCbVVuUjFObE4yYVNVeVJuUnZUbUphTW5VNGJVbzRKVEpDTUVRbE1rWjZRbFJOVEdkNmNIbDBRakV3UVVVbE0wUW1ZejE2VmpCQldsSldXVkphWTA4MVlsb3dkRVUwVGpad0pUSkNjRFJhUmpCM1lsaEdZVkJ1TUVONE5IRWxNa0o1WkRob2Jsb3hRa3d5U1d4MmNWWkhRWG9sTWtKV2JTVXlRazVpVUc5bmJtUm1hVTVVWkZGbWNETlZXbFkzWjFCMllWSXlPR2cyU1ZGQ2MyZEtRblV6VmpWS2RWSjBUak0zVUZkQ0pUSkNUMHhzTVhkSVZYRmtNME14TkRrbE1rWlBPRXhzYkdad1YzUklOSEJYYUU5SGVsTTNXbWNsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYm1WMFkyOXNiMmR1WlM1a2JDNXpiM1Z5WTJWbWIzSm5aUzV1WlhRbE1tWndjbTlxWldOMEpUSm1ZWEpsYzJkaGJHRjRlU1V5Wm1GeVpYTm5ZV3hoZUhrbE1tWkJjbVZ6VW1WbmRXeGhjakkwTVY4d05USTBNVFlsTW1aaGNtVnpjbVZuZFd4aGNqSTBNVjlwYm5OMFlXeHNaWEl1WlhobEptUnZkMjVzYjJGa1FYTTlRWEpsY3kweE1qUTRNQzFrY0M1bGVHVT0=

http://www.presentheartapplication.com/WVl6OTRQVFJTUkZCR1NXUldXbWRrTjFJelMyRjVaMmN4U2pOQlZFcDVhRlY0TnpCSldFMXhaRGN4YVVobFlqZ2xNMFFtWXowMFIzUnBhMVpsWVhCUFdGRkRXWFpxYVc5WGVEazRVRGR1UlhwaWVHRkhOM3BMVVdoVVNHVkVUek01WlRKUmRuQkVXVFpVVGpBeVJtaGpiMGw2U0ROQ1owdzFWMFJwWTNKcFJFVjRVVTVKU1ZKSFEyUnhOVkZSY1hJbE1rWkxZM1ZGYTFWck9DVXlRalZXVUVjelFsSTRXV05TTkZaelZrZDZaVTVDVVVWdFYzaElibWMxVmtWWE9HSXhkMUl5VUVGMUpUSkNKVEpDYkU1RGEwTlFkeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp1WlhSamIyeHZaMjVsTG1Sc0xuTnZkWEpqWldadmNtZGxMbTVsZENVeVpuQnliMnBsWTNRbE1tWmhjbVZ6WjJGc1lYaDVKVEptWVhKbGMyZGhiR0Y0ZVNVeVprRnlaWE5TWldkMWJHRnlNalF4WHpBMU1qUXhOaVV5Wm1GeVpYTnlaV2QxYkdGeU1qUXhYMmx1YzNSaGJHeGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MUJjbVZ6TFRFeU5EZ3dMV1J3TG1WNFpRPT0=

Latest 30 of 56 download URLs

Remove ares-12480-dp.exe - Powered by Reason Core Security