audacity-11826-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application audacity-11826-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
5be4ab60a9b74212411cf254ee2e728b

SHA-1:
367affbe6f80cb1a834990b6233c179464e1bc47

SHA-256:
3ba761a9c77d21b463e0976bdc7a34fac9647c35da2f43b632ef5bed6a6b4ce4

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 5:54:51 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.17

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\audacity-11826-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:qrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file audacity-11826-dp.exe has been seen being distributed by the following 20 URLs.

http://www.worlddlstock.com/WVl6OTRQVGxhWVV4dlpsbExSbHB5U0haRlZrUkNVa0pvTTNab2FtdzFWRGRPVFROaUpUSkNlV3RFY25aNU9IUTFNQ1V6UkNaalBWTXhZV2xCYWxsSFJtOWpOVzg1VEVKWVkxQkpSRWd4V2psQlQyMUtaR1ZaZEV4SWIwTTJibXAxZDJ4clpXTklUR0VsTWtJNVFXdG1XVU5IU0d4bGNHWTRNWFF3YjBoUlRrNUhkMmRTVEd0VGEyMXNlbGRHVFZNMlowVndhVkJhTTAxNU9XMVNlVFZJVXpOWFFuRldNaVV5UW1aelZTVXlRbkpPYWxFM1RHaHhSVzF6VTFsRWJXMVpOMDF6WVdGRU1GZ2xNa0pPZEcxbWFVOUxXV2hSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aa2IzZHViRzloWkM1bWIzTnphSFZpTG1OdmJTVXlabEJ5YjNSbFkzUmxaQ1V5Wm1WNGNHbHlaWFJwYldVbE0yUXhORFV6TXpFd09Ea3lKVE5pWW1Ga2RYSnNKVE5rWVVoU01HTkViM1pNTTJRelpIazFiV0l6VG5waFNGWnBURzFPZG1KVE9VSmtWMUpvV1RKc01HVlROVzlrUnpGekpUSm1OakkwTkRZelpERmhNems1WW1RNVlqVXhOakUwTlRjek5XVmtOalprWWpneVpESmxOemczWkRreU1qaGhNV1F3WWpjMk1qTTVaalkwWTJNM01tVTRZU1V5WmtGMVpHRmphWFI1SlRKbVlYVmtZV05wZEhrdGQybHVMVEl1TVM0eUxtVjRaU1prYjNkdWJHOWhaRUZ6UFVGMVpHRmphWFI1TFRFeE9ESTJMV1J3TG1WNFpRPT0=

http://www.grabappsdownloads.com/WVl6OTRQVU5oV1dWSlQzbFJjbVF3V0hsaWEwbDNia2h5ZERoYWRWWjNlbnBrUkNVeVFrUWxNa0oxU1VOb1dGaFhNbGRGSlRORUptTTlTVzBsTWtKbldscERhMHBsU2pKWE9IWTFkamx0WjFsNFptaFFaRkV4UkU1SFVrRXhKVEpDYm5ocldUTkxOM0V5V1VGc1YyYzFVMkZxUzBGRFpqQXlRM0J6VkhKV1FrbEJaSGxKV0hCaWNXRnhjbEpEZGxGT1V6aDNia1lsTWtKdlFtcHdVVFp4YTJ4bU1UZGFaRVJoUVZaMk9YUm1TelI2UW10WVJVVjNWelpsU2xCRE5sZFhSRkZ0TVdoUlUwaFhZekpVVVNVeVJscGthblZ6WVZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpZU1V5WmlVeVptUnZkMjVzYjJGa0xtWnZjM05vZFdJdVkyOXRKVEptVUhKdmRHVmpkR1ZrSlRKbVpYaHdhWEpsZEdsdFpTVXpaREUwTlRNek1UQTRPVElsTTJKaVlXUjFjbXdsTTJSaFNGSXdZMFJ2ZGt3elpETmtlVFZ0WWpOT2VtRklWbWxNYlU1MllsTTVRbVJYVW1oWk1td3daVk0xYjJSSE1YTWxNbVkyTWpRME5qTmtNV0V6T1RsaVpEbGlOVEUyTVRRMU56TTFaV1EyTm1SaU9ESmtNbVUzT0Rka09USXlPR0V4WkRCaU56WXlNemxtTmpSall6Y3laVGhoSlRKbVFYVmtZV05wZEhrbE1tWmhkV1JoWTJsMGVTMTNhVzR0TWk0eExqSXVaWGhsSm1SdmQyNXNiMkZrUVhNOVFYVmtZV05wZEhrdE1URTRNall0WkhBdVpYaGw=

http://www.grabappsdownloads.com/WVl6OTRQVlpyUm1wSE9UZFpkMUF3YkhWQ1p6Qk9ZM05aUkZWaE5TVXlSbVF3VFRoeGFrRnFUeVV5UW1sbVJWbGlaVVJOSlRORUptTTljMFpVU2trMlExcDFObWNsTWtKd1ZUVnJjbFZOZEZBeWVqRkZhemtsTWtZeVpERkdNMnRRUlhCc2JWRjJSRGRIVEVZbE1rSkxkR1pFWlRObFJsWnNVa1U1YmpOTlIxTndKVEpDYlhneU1FVlRVbGxtWkUxR2N6SkRZblJ4VkRGWE9WWjVjMlozZUhsVk4yTjVPVll4T0hsSVVFSkNORWgxVWs1VGFVaDJNVEpqTjBkV1lsVXlVWHB5UWpFeGQzWnJRekJwUVVNMGNYZEJhSEZOVlhjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpZU1V5WmlVeVptUnZkMjVzYjJGa0xtWnZjM05vZFdJdVkyOXRKVEptVUhKdmRHVmpkR1ZrSlRKbVpYaHdhWEpsZEdsdFpTVXpaREUwTlRNek1UQTRPVElsTTJKaVlXUjFjbXdsTTJSaFNGSXdZMFJ2ZGt3elpETmtlVFZ0WWpOT2VtRklWbWxNYlU1MllsTTVRbVJYVW1oWk1td3daVk0xYjJSSE1YTWxNbVkyTWpRME5qTmtNV0V6T1RsaVpEbGlOVEUyTVRRMU56TTFaV1EyTm1SaU9ESmtNbVUzT0Rka09USXlPR0V4WkRCaU56WXlNemxtTmpSall6Y3laVGhoSlRKbVFYVmtZV05wZEhrbE1tWmhkV1JoWTJsMGVTMTNhVzR0TWk0eExqSXVaWGhsSm1SdmQyNXNiMkZrUVhNOVFYVmtZV05wZEhrdE1URTRNall0WkhBdVpYaGw=

http://www.worlddlstock.com/WVl6OTRQVWRuWnpONWRFNTRjamxTZUVGNWJWcHZhVmhHT0VSR1lsYzNZell4VkZvbE1rWjRPRVEyVG5aT05FZEhSU1V6UkNaalBVTkhhMlZyZGpFMVNrMXNSMlJUSlRKQ1EwcGtVVTlaYjFGdU9XWkhUbnBHY1hCblZGQXdKVEpHZGxoc2NUaFZkR1JxVldwVGJHVktXbEkzSlRKR01IZDNiM00wVlVWRGRYTllUbkpaTkRoYWJGTXhRbXB2VTJsME1qbHZiWE5RTm5KWVZtZzRWek0zYUdaRlZWQlNaVXBLUkdOU1VHTnNNRU54UVU5UVpXNXBUMGxuVjJkb2F5VXlSbTVTSlRKR2FVcHhRMG8wYmlVeVJtNVphMjFVY0VreGR5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQnpKVE5oSlRKbUpUSm1aRzkzYm14dllXUXVabTl6YzJoMVlpNWpiMjBsTW1aUWNtOTBaV04wWldRbE1tWmxlSEJwY21WMGFXMWxKVE5rTVRRMU16TXhNRGc1TWlVelltSmhaSFZ5YkNVelpHRklVakJqUkc5MlRETmtNMlI1TlcxaU0wNTZZVWhXYVV4dFRuWmlVemxDWkZkU2FGa3liREJsVXpWdlpFY3hjeVV5WmpZeU5EUTJNMlF4WVRNNU9XSmtPV0kxTVRZeE5EVTNNelZsWkRZMlpHSTRNbVF5WlRjNE4yUTVNakk0WVRGa01HSTNOakl6T1dZMk5HTmpOekpsT0dFbE1tWkJkV1JoWTJsMGVTVXlabUYxWkdGamFYUjVMWGRwYmkweUxqRXVNaTVsZUdVbVpHOTNibXh2WVdSQmN6MUJkV1JoWTJsMGVTMHhNVGd5Tmkxa2NDNWxlR1U9

http://www.stockbundlecentral.com/WVl6OTRQWFF3Ym5ZbE1rWTBTMWMxT0cxTk9VcDFSM1YxUjNCSE9FbGFiV3RoTTJSTVF5VXlRbTlaYzJwdGIzWTNXR1YzSlRORUptTTlUeVV5UW1KTFIwWnNkRTAzUWtGSmJpVXlRalYyYVdWb1YzWk5UbGsxVlhNMFkxVm5ZVEZQTVc1cmJpVXlRbFFsTWtKd1IyeEJVV1Z4YldRMlNWZzVNVkZYWWpSMGRFMWtSa3Q1ZG1oV05FNTBOekJ5TlZwWVQySlNiU1V5UWpCQmRrZEVWMmw1YURsWVUzTTVjR1ZqV1NVeVFpVXlRbG93SlRKR2RteE1ibTgxZGxVbE1rWmxlV0l3Y21kS1QxbEJRemxWU25JM2RqTkZZM1E1T0hST2QyRlhOamcxTTBaQkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNITWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW1iM056YUhWaUxtTnZiU1V5WmxCeWIzUmxZM1JsWkNVeVptVjRjR2x5WlhScGJXVWxNMlF4TkRVek16RXdPRGt5SlROaVltRmtkWEpzSlROa1lVaFNNR05FYjNaTU0yUXpaSGsxYldJelRucGhTRlpwVEcxT2RtSlRPVUprVjFKb1dUSnNNR1ZUTlc5a1J6RnpKVEptTmpJME5EWXpaREZoTXprNVltUTVZalV4TmpFME5UY3pOV1ZrTmpaa1lqZ3laREpsTnpnM1pEa3lNamhoTVdRd1lqYzJNak01WmpZMFkyTTNNbVU0WVNVeVprRjFaR0ZqYVhSNUpUSm1ZWFZrWVdOcGRIa3RkMmx1TFRJdU1TNHlMbVY0WlNaa2IzZHViRzloWkVGelBVRjFaR0ZqYVhSNUxURXhPREkyTFdSd0xtVjRaUT09

http://www.stockbundlecentral.com/WVl6OTRQV3BOUkZJd1dERjVZakpoY0UxdlVETlVVME4xUms5RVJEbHdTMGxETVZkYVNsQXlKVEpDVDNCSWFrWnFPQ1V6UkNaalBYVmxSVlZKZFhKclprUldWbFZxYzNoQmF6QklXVTVGWjJ0TU5sQkZNakZEZUhOalZuSnNaMmwzWmlVeVJtTTVkSEpyVkRGSGFVeGhjMVpFVFRaMFZEUTRhVEpJWTNGaFRVNU9PRkV6Y2tSTGFVTnlORVJhZDI1SVYyNTVWVkpMYlZnd2F6ZFVKVEpHWkRGSWNuaFZTa0pqTWtOMGRFTkdWaVV5Um0xcFdFRlhUWE0yVm5WbVIzWkljV3c0U0RGRE9UZGpUMnR6Vm5OblZYTnFVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEJ6SlROaEpUSm1KVEptWkc5M2JteHZZV1F1Wm05emMyaDFZaTVqYjIwbE1tWlFjbTkwWldOMFpXUWxNbVpsZUhCcGNtVjBhVzFsSlROa01UUTFNek14TURnNU1pVXpZbUpoWkhWeWJDVXpaR0ZJVWpCalJHOTJURE5rTTJSNU5XMWlNMDU2WVVoV2FVeHRUblppVXpsQ1pGZFNhRmt5YkRCbFV6VnZaRWN4Y3lVeVpqWXlORFEyTTJReFlUTTVPV0prT1dJMU1UWXhORFUzTXpWbFpEWTJaR0k0TW1ReVpUYzROMlE1TWpJNFlURmtNR0kzTmpJek9XWTJOR05qTnpKbE9HRWxNbVpCZFdSaFkybDBlU1V5Wm1GMVpHRmphWFI1TFhkcGJpMHlMakV1TWk1bGVHVW1aRzkzYm14dllXUkJjejFCZFdSaFkybDBlUzB4TVRneU5pMWtjQzVsZUdVPQ==

http://www.worlddlstock.com/WVl6OTRQWGw2ZFZKR1NXVkRjMk5PT1VsalNuTm5kM1poV210UE1tTndZMVpNYjJoS2NYZ2xNa0o1UWpGcE5TVXlSbTVOSlRORUptTTlOVTVCY1Zjd05HbGFXV3cwTmlVeVFsUm5VRlpGWTFWS1dUQmFXbE5aUjNacGNUSmpZVE5KYUZsRVl6aEZXalpoUjFGM1ZYUmhNbkk0TUZsYU9FYzJibTlMYTFsb1VEaEtUMDR6Wm1WaFlsbFJTa2RwWXpKc05sSjBVSEJLZDFSQ2VFUmxNbEJ6YW1sVGNHMDFURVl4V1VFM05uWkhNWGgzWm1JbE1rSjNabUpMYVdWNFZXVmFKVEpDVDNVd09VWmhlRWNsTWtaUVpFOGxNa1p1WlhjNVFTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQnpKVE5oSlRKbUpUSm1aRzkzYm14dllXUXVabTl6YzJoMVlpNWpiMjBsTW1aUWNtOTBaV04wWldRbE1tWmxlSEJwY21WMGFXMWxKVE5rTVRRMU16TXhNRGc1TWlVelltSmhaSFZ5YkNVelpHRklVakJqUkc5MlRETmtNMlI1TlcxaU0wNTZZVWhXYVV4dFRuWmlVemxDWkZkU2FGa3liREJsVXpWdlpFY3hjeVV5WmpZeU5EUTJNMlF4WVRNNU9XSmtPV0kxTVRZeE5EVTNNelZsWkRZMlpHSTRNbVF5WlRjNE4yUTVNakk0WVRGa01HSTNOakl6T1dZMk5HTmpOekpsT0dFbE1tWkJkV1JoWTJsMGVTVXlabUYxWkdGamFYUjVMWGRwYmkweUxqRXVNaTVsZUdVbVpHOTNibXh2WVdSQmN6MUJkV1JoWTJsMGVTMHhNVGd5Tmkxa2NDNWxlR1U9

http://www.stockbundlecentral.com/WVl6OTRQVEpzSlRKQ1ozUnlXV3MxTUZOVmVIVnViaVV5Um1kdlUxbE9XRGRVUTJKM2EwRmtRbGhGYjFaMFJtZHpaamhuSlRORUptTTlVVmd3T1NVeVJsbE9aMWxGWVhkdVVrbFZXREJ0WVRSVVRuZHljMFZFVkhwcVNuQnJaRmhSWjNkVFRrbGtTSEpGVkVwa2FWQm5jbUZWTlRoblRXMWthV3MwT0dSSWNuTkRhVmN6WkUxNFZuQkVhVXBWY0RSWGN6TlJSM1ptTjFWaGNVeEhiV3BWTkhWMlJWRXhRV054UzFsak1XeGxlbFJqU1hWTVEyc3phVzQxYjA5SmNXUk5TVWhvTVdodllYVTRlbFZNT1hKdWIyY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6WVNVeVppVXlabVJ2ZDI1c2IyRmtMbVp2YzNOb2RXSXVZMjl0SlRKbVVISnZkR1ZqZEdWa0pUSm1aWGh3YVhKbGRHbHRaU1V6WkRFME5UTXpNVEE0T1RJbE0ySmlZV1IxY213bE0yUmhTRkl3WTBSdmRrd3paRE5rZVRWdFlqTk9lbUZJVm1sTWJVNTJZbE01UW1SWFVtaFpNbXd3WlZNMWIyUkhNWE1sTW1ZMk1qUTBOak5rTVdFek9UbGlaRGxpTlRFMk1UUTFOek0xWldRMk5tUmlPREprTW1VM09EZGtPVEl5T0dFeFpEQmlOell5TXpsbU5qUmpZemN5WlRoaEpUSm1RWFZrWVdOcGRIa2xNbVpoZFdSaFkybDBlUzEzYVc0dE1pNHhMakl1WlhobEptUnZkMjVzYjJGa1FYTTlRWFZrWVdOcGRIa3RNVEU0TWpZdFpIQXVaWGhs

http://www.grabappsdownloads.com/WVl6OTRQWFpSZEZGbVVVbEhaVE5rVnpGQ2JHTk9ka0ZUVEUwM2FUWkxUV1JCWW1KQ05sZFFlWGRWYjJVMVkwMGxNMFFtWXoxb1JucEdjRUpFTmsxb1MyVnBhR1pqUzFoelVWZHZaVmcyYm14WWVTVXlRbEEzVTFkaVRVVmtjRXczYTFoNlYxRkdla2NsTWtKbWRHNVVRV2Q0WldoNFZrZEdhVE5wYjFOSGNUTkNka2xTV2xoWFVrOXRWMFpsVVRWdFdYVm5ieVV5Um1aaWQxQnJVWG8zZEZnbE1rWTVjbXR2ZEZsaVRHaFZNbEZoVkhwUlMxVmxOSEJrWVd0SFpWaDFTVTF4TVdvM0pUSkdZa296WWs5MVp6bG5iVEpuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aa2IzZHViRzloWkM1bWIzTnphSFZpTG1OdmJTVXlabEJ5YjNSbFkzUmxaQ1V5Wm1WNGNHbHlaWFJwYldVbE0yUXhORFV6TXpFd09Ea3lKVE5pWW1Ga2RYSnNKVE5rWVVoU01HTkViM1pNTTJRelpIazFiV0l6VG5waFNGWnBURzFPZG1KVE9VSmtWMUpvV1RKc01HVlROVzlrUnpGekpUSm1OakkwTkRZelpERmhNems1WW1RNVlqVXhOakUwTlRjek5XVmtOalprWWpneVpESmxOemczWkRreU1qaGhNV1F3WWpjMk1qTTVaalkwWTJNM01tVTRZU1V5WmtGMVpHRmphWFI1SlRKbVlYVmtZV05wZEhrdGQybHVMVEl1TVM0eUxtVjRaU1prYjNkdWJHOWhaRUZ6UFVGMVpHRmphWFI1TFRFeE9ESTJMV1J3TG1WNFpRPT0=

Remove audacity-11826-dp.exe - Powered by Reason Core Security