baixar-musicas-gratis-3-8-0-32-bits.exe

Swift Funnel (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application baixar-musicas-gratis-3-8-0-32-bits.exe by Swift Funnel (Fried Cookie) has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from d.baixakifiles2.com and multiple other hosts.
Publisher:
Swift Funnel (Fried Cookie Ltd.)  (signed and verified)

MD5:
e7207388be3cd2a3ed7a474fbe1a44ff

SHA-1:
b4d50500486908e9e9d8cb06420fd7bd8fafd536

SHA-256:
53128b0d5fdcf490b297ed18e07bce43ad1c74f4dc9de02854e671eba0e791ff

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 2:02:11 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.186.230

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.141128

Comodo Security
ApplicUnwnt
20121

ESET NOD32
Win32/InstallCore.RO (variant)
8.10742

Fortinet FortiGate
Riskware/InstallCore
11/28/2014

K7 AntiVirus
Trojan
13.185.14057

Malwarebytes
PUP.Optional.FriedCookie
v2014.11.28.07

McAfee
Artemis!E7207388BE3C
5600.6932

Qihoo 360 Security
Win32/Virus.Adware.94c
1.0.0.1015

Sophos
Generic PUA LE
4.98

Trend Micro House Call
Suspicious_GEN.F47V1114
7.2.332

VIPRE Antivirus
InstallCore
34894

File size:
698.9 KB (715,672 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\baixar-musicas-gratis-3-8-0-32-bits.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/4/2014 3:05:02 PM

Valid to:
11/5/2015 3:05:02 PM

Subject:
CN=Swift Funnel (Fried Cookie Ltd.), O=Swift Funnel (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219222B1C3CFE5BB71BCB5117BC2A44FC6

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:HT2aBIZBhDJLKc7NlZ2llDPkRZ1PZZrspGqNUHUBxvrQkgEm/XFjwHXwAbd2yZR0:HT2YIlw2yDMRdZrxqNyUB5rQkklwHvbK

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file baixar-musicas-gratis-3-8-0-32-bits.exe has been seen being distributed by the following 4 URLs.

http://d.baixakifiles2.com/?ic_user_id=254&data=AioEuGbo3XoOVXZkixRbgyZgANf1u 6BbyUjgguqJQ2f4ySHb yuOV o0bjkveSIXwTlaKOsp6Fx0x pH0LlHozXNKZKud1g5LxUZCRzYqBguwFD Sj0k10Jj8oJF0ThyD6ig2 4XaETCsjMnj Yeu8/r5j/P3Mo3XoOQ6f3GYihAZUp2f1DfWuUPGDl64qZrif88Mc9PtXa xK3jblABJ8d96rkzsZ SD3DEL9hwLX4iPxmLTdHfF88YxDYn6W3GELn5AhR6H9Z un944AhVtXvgHv8PRtmBlh1Y0t5Fqejt36feGYIrTwqirBdbNpTl PYF3NbDXpSPPRVTJDiJBRjxVMVlOklpMUb E3Rk sb9IbMiPdvt4mywtBDSzzZO0m12WOLtkZTuPJnDSxgnv/AzVkTgFhZKcrPv4d6nVkT5Y6fe9prLQpKlXunpJCRTcj/cDdjjkWGiljEu4 5vOZBJ68eKrZHHeqEvDCMcQ8ntA PmPrP8YBy9RhZq8/MUrdb ApYB03EpAaELQvSWemT20RnZQG3YG7TdGCqH4Hex2p3Gm KFNcK7/l1rTdJjK4yktCXFlWLNQxR3wlGwjxXWKbVd4vgePFeFYt/lf2mvuxqZvdFB4/Z 8jqINXszKyPPUn2Par7q65FZmElCHg4G0qbq3 jfwqjQHgLlvM3RVh8FszXtaEDYYmlNNgktY8W52 /rDiv0CXvt/kbS53ryKtsgMrjBgtVUMLnrTyxxhtBgT1keISZ8R/C6LNRtVDiMYCFJNRG7x/.../JH Sw4uAWibpPIYE876n7rkcMGAvqm68X6DyzHK7di9UDT1rtcq2fSsTV8Ce3W5ZCFlQ4R1RUZJK9nquh8P4IVGRxdk bV Ax3y00IZCBet2neyAVQxiazSJhJgh3Bq5yK693V28kTVkH2vg

Remove baixar-musicas-gratis-3-8-0-32-bits.exe - Powered by Reason Core Security