bitlordsetup.exe

Cohagamo

House of Life

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application bitlordsetup.exe, “Cohagamo Setup ” by House of Life has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.cleanchucklemeta.com and multiple other hosts.
Publisher:
House of Life  (signed and verified)

Product:
Cohagamo

Description:
Cohagamo Setup

Version:
5.1.2.0

MD5:
1aa26724f1b792eb5999b48ae276502a

SHA-1:
7d48ef6ae42cd3f92d68e46fb95463ec98b679f3

SHA-256:
4cd4654e7a7a0af8d3f68b52520c6073f358532a2d74a7c4ff3c6825a8f6c1b7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 4:30:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.HouseofL.Installer (M)
16.5.10.10

File size:
1000.1 KB (1,024,096 bytes)

Product version:
5.3

Copyright:
Software App Wizard

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bitlordsetup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/11/2016 5:30:00 AM

Valid to:
4/12/2017 5:29:59 AM

Subject:
CN=House of Life, OU=IT, O=House of Life, L=Sogndal, S=Sogndal, C=NO

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0E8FFE1E4086A8FB13C069E8E8571F82

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:yEEaZhpldJwTGveKpBW0cNk+W2A1InyWzfM3D9DXpGX4V0KdcwXdblSlbzK+:yEEOzdGqveuTbZpWzoD9PJAl5

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9269

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file bitlordsetup.exe has been seen being distributed by the following 50 URLs.

http://www.cleanchucklemeta.com/c?x=1HTtPlurzA8hsWE/w/tWVf9wnN 13bls3Vcztm9eLE4=&c=8St64axUAgqAOe4Wzom1ztZdlDe3vCmeWkDsQsZX8Ge7jhm4iFPwEoSNRvh9UDW4LJpz8j/koPjGpx4xkIeLZj5VMqYBRxPWBka5cu5sK0iwd2PpVW WUR8TCYULiNaetVzmNO3lCPmtssL5gl10 D7DOOBxDmTMoRjikpqu3lMz70bQW nZxt1VVGREavor&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=T594geAntFxDv2K//S96jlcRVykVYnVNxKhfdcvZTLs=&c=ufSYD0yVov36rN4fQ744sxgRntXlXEsjabhESlrvTO5frKItX4ebr2DdNiacyrkNPIbvGkED0Hftx7lYiAdXrDn12zlsdIoDiFZjCtTEQgzJ6ASJUrXMeahEJcSsi4J6RhtKZ051OAakjGsyT5gTYA==&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=sI/NSE7NbvKI1Gc4sx9fwIoZwxeoZAukijK0fz7ruzg=&c=LFsAWOTKKh bm7hHmjvU6SR4BdvKONAQkROvOvAAPB0SCuA zTNS3dK2m9zCkocK0TopSui cwtB14mjYk5gBR Hch4Sl7pFR/IQe/FzzWK3id3XGCGPmX9vS/NowfY4SgYzLZyzmiQm09s 6cKUaeJPY4rkClreLB 5EOJ5dqQ=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=/GIdH6iMnGBDhbPzs5PMfNM0/GjhjYqnXzcVlvdngPM=&c=ueSJ7ZcB5UR0wjMAnHuF/4ALGxwJGc8Jy6b4oDFzu5AzI7sBS3wfQQjpbU2p/UNv0SGa0yYHd ZnlQr8CZMlRY5c7DPhVgDkQ5gaHPb95N43LfpzrMzLbqIPiWuBS3UGEvTLocYYYdcIGP n9HweE1D/oRfsw4pX3Tmq49G5f4U=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=RCPhgPqwGEwwC1CJeJrSs96p/4J1Hdk yLL/N/IGJJ4=&c=Y5cMdCf p6OsUml72G2LPiXsFNDLM219a5M9nATYzNhex9xK9Ocs6K2F6LKNw3 ZPKqeJPfHhs629KB5Qh/iSeyXqBvDLcxIUaq EiMO0HhReqB0I T/nzfuOT0CEwZzfBSZ3 qyP0982cH57nnd5e4wc1 j01MQ3W1kCV/VDKY=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=32noyPd5kyunU2J9Pi8Q1thd7GWBeaVakViYpS4ZvG8=&c=YSsHBMczR1f7xQewW8q8sWJyoXvj RoAsGcKLUBotSGecgoolbECYWDZPCwAVaL7D TvyerGlsLRp5YUTDhSeyP3J JOSMnE7fIQtgVn4uwaeHymsG2EUyF4fim0QYRPh/IwMf9 NuFTJ/8LPJ2r6o8jVrpvZ40 rtBDoYAtOnTKk0sMiiVcbFsoop29jdxW&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=4gX1WtQmewNRYNJRnT6NRYFmoao2II3XU/5QLoO rVQ=&c=SZ3qcz3OW24aUCjDB28qkhSwl0xRH6aqsYr3J6fF5Idfedab809SrCVPBttBzdSoHh6j1 dMc9tEUOmfpxNufICTKlk 5dehBHBFwVch/ASAUqU9azkK9WDN/P/F3 CGV3MBbHV0JFR9TN4Mfe566N0r8h8WP f9T2oSaRRG4uc=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=mokPHO0hWU17VXr0yjhTdBdmaeAx5r0l5M0bacqb1gg=&c=6g46tk07NSx1gIAdDdmPZaxwIrxLlw3GTzCFOzp3oqvLEEK0I49DZLKX9O qfpn5WmRQNS6U9OTn0FuG8Wp8DG9M/mlIp1u4yN gYtGCaRPqhtLqEMuNvomzKSkXLw46E9fAoQpaEhYCk00F4n6o7WQDZV2oSZfwFvYcAeHyGohF1Mrs1ICqnJwYqF8WtqB6&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=PO6sYXfs7xgeKh06XrcUBYu8hiZ1EL4p5lsSb7gq7UI=&c=Iqwvdzc52YF7RPJ1eMy056DIQqhappbO/oaHODh16vEbbS1pCDaMj6nVkX9O781TBnZbdZSZ/LGfya2XP0mD2yggPGYanBj4o kcrhdVoH7nhZrYKTIXAD9sO6aIDx4qKGHgjY0dMCTJYjadVONWExh9v6E7JB5zIyHhuCd2VXczGfTBibf2ujiH2IenO5Mz&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=lzIRob4/3gXGsqEfE/1jy3ku8MKH5oQoXTd9f9o1Eoo=&c=GA9X/ewDxGon178fisomJJOpQTwDabSP fxUruZwFZP98EOMAkyCLDaH jZJS3LGngTMUL1M6AE3EiX7ZJ66crGA8xxiPgGRseqIuFNAq22/k2REPr5Q9q3qbH3ukNc1BhGuVOD3cF/zQlXAcfyu9IjBDdvhIV4O6BkFBDpQOA8=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=lXOwQ54U6WLivwO/tykc43m Nld3NZRPn5nfj8LsMmQ=&c=3cNfOiPJP9MrK17Uek8eefTGc9ZHPTtZXxywBLgpCBkaQNRor44EX rE 87al4Ouqgj/K98DTtQmvWzcmrjzYAH4iok/jWm oZu8BFr8jpr1UH G8kmm gfpyHak4o72lz3BqwLia4gCvmae1pYsW2i/KyuPtYkA hAyzsSDM5W4lBQO3RYkjrJmCg33WPuH&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=Ci2VjEyv8yqAX4FmKHpPUPLdnciGVElfd5SdwggLkE4=&c=Z4UYRDgau MoUyJIcgukSzHNB9iF2 AbDChrN4Fch4K0UTDm FeGfLyrf1fCgqGZdkIAT8PaQnQ4stfN0d8 QlWigMs/CxBJIDsv0j/QjQ1Avs/WdWtWo9y6Mz5ShbUufouk/TodiZL3wKgrxmwIEjwuIwL9So5S0PcfVblqQsQ=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=fhhWRTTGl41gRCaZprwB2td7atLumdRoldR b1DON7o=&c=lkDUp9rKxMEjXf6WJjkkeOJunBW0uVPCpcWGiQvRXkOIVOjkVfogkU5vkxoclG3QmaoBMT5/ BcEyOUCfSUvfTR7HDAWUe6Hp93TUo/QJecQt lz8642I6a1uIIE8noBi/mJQ8Z5PMC6VeFtxxy65U35QzZe4vYrKFyz60cMTtI=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=ypXRisthZJdoNc6KZebMObdA4AIiWsQsUUhf4xHQwlI=&c=y2RovFKG83liueJsLbgkAPGtDzMoPeYQwzoerv0SkeNXediYGYT/ZS8YgzDzNBhRF40g6KtjtKCZ2D54EPKkq0RJ2UnfWZDPGtTPbeyrFjwRAE49x/ZcHmRD927pzY8SVATyMxFCzBjJTNlnIvo5Jj6f7kGwEQ/NHDX jeg/Uow=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=XzDCJjgyNs XzD9ezIGQ4NVq2fxZWerYRFZMuPryDdw=&c=tEAsISTePOaY4UIp22sJAYVt kCxCnwTaVRlHV9Fjb199 iS/3zEzU4aSQa EpEf41vp/5rwCunN6Oj5bwr3955GjWKBtmD1jYoBLGriGXkSRKI9wobkbGjfH0CohKRPUAQ7/ esHkSpYOKOrf50hCezMSYhlExl//QKXMRxEc4=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=cxJ9lIAEciezNl7NEKTVfgWus4uKMERIhzk QU1hONo=&c=NZ5DPv3PUzPDms/tdVIq5Osn/NgxSG5316yrbeAkRyPFtEujAeGolEpbNRJI4VC0BC ipzjHhe/hzuEuT4ydecyt44LiJCXmpv0jKD5KdDOO6trszcy36gqvzWUqWb2IdUOc5H/CznDSpIkEMszoHax0HolyZNwH0Xfc6AZS6mem4Zt7mm3H6jz3foXiKDAT&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=UQ3gmL0IPy2K zA8omVofcCFzUA/JeJKpn2yiN85yOg=&c=NPOMkwJk9fp8Sdtl B3P45HVCBIibhI4GqauzHi5idBBdm1A yTD83JwPyIbuptVi3SySWhyiiIb59xbbXH5sJF27AVQwIlddeeJ7bh77SbWM03mbSJn2S5w7bhAeb84VHj1zfwjG9WDyF9F6QjBW0F2N4cAuU3hwHfu1lkQ VacK8RbGNr892va9jrR4V5 &e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=XfSPsJVJl0O87gMe7p41EZs0AlYOFaAgDwZHve/TLIo=&c=V3vgSK6QwD0aUcqj2SGrWqlctMGrLGMrG DUZ53THpg45jJWritoyKwZGJkkV/JAsjm3l72Vj62LWnFaLly6vPk6Pa4HxJFEMzCTSxHKxWiXIS2AIUOtFICYA7 7bb2Jfc6ZUYqS NJ00F8CGznaud7mRCw0V8feFhvmhbl/muotX g72WiAG5egzjtm3rFa&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=AK5vy9B3RUzqVWsqU2nT2BFWDqJ8IZUykfQoMlvjujc=&c=iiOOcvCbLVtzhUhOyccgxQrkcbUjWt0yEwz62luh3Irm7OGtlZPyGY7 IR/ubVZ6kIUpN5kjVnioGTP4B kS Ls2WXi6TlCMKK6bSwhBFliDyLjH24u0XeiCGxSI0Ear5gaMDPabWnNKcFsxU0fSXDTx3M/5spLioc aTGtHI58=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=MjNyOcAItBceILNipP/9amRw0NdW766qK01Zi8OGNDU=&c=8lnlX/eVAu6Bl55ip15Aamd8W4GwEPAGmxfOx7TZACrEVGFiuFjH6RbSPBPvSNCsNK2ZxiBmOzASyvWyls0VEnjsWtNwxmFKesPyLXnXJk6FTJfjfy i UrqwMuj9pRjWHcVRwDv1Ejec8sBtI8r0si6xvNMsqGoqsbI4LYeGy8=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=ckRAP ktUXAhWIF9LpoZcpyCVPrlT6H7nYDbGO4Mo9o=&c=XUMqjKCWTFza9/r6tSVdt29IhulzcTu5JrRTctMkMmgJ0WgaVYoIsUFaqBAyqOETSBWwofflq9ZFn0UzsaeR4WTBSWfVGj17qi7mKVTCytbiq6tvVgJcudzpRkH37LPgN6GbGV98IZ4xGTLJuF/TVft00c 8w1n1ssEMBO9VzUtiljy0uhhD 7m5k8FBtw/z&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=/xzTsZpNKQyW9tMhl3DlNc/i5v5Kgfkh4L8LELvlTFk=&c=8FRtq8Wdy WoDI3qJD3nOW1UzfjltuHWfijcsrJCk4mse2fFfIWATYkVq2DYiK9GaEQwpZowxFhJrap3Wpz/UIndzhP5V6Kz9Se4vWsBhoItmAPmdwo7uq3K7oNMsngkzLMXyAHOsCf0kRl8w4oC6DMv7IETGa6O3nB tROndhg=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=arA1PNaudD75dcFK762lmU Lfzb hkhCBO5zqSSOUUs=&c=YcLZCzBrl4qJ78XgqPeq3GLDIBBN8L3MgWZbiaW3rE9KXx/rHRsYJy5bxsUlt11UICQdbMKHDGwaJ7960cfNuoEvQqVUb1p7RG Ijjt8 paQYn8r9e6N9D4wOyhpNu6oyxrfuCqe3dBdlkC9urGFJca3oEDC/Efz5tXfOop/lXE=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=ofCnK9tF689iQNyhRLl6Ebua/9Vk78YsI 9/3ASZbAA=&c=EJ/AE6KZNt2GZdUP9nqFbkNaZb5k9GEJYsJ BYKylW3fFNOM/X6WCwFDOZ2wdUhwosGpdTYi5FXHJTsjE2AqyvVO506sUd5gzT owlrSvhz3H8rCgyhEk5UAcP3Y9SW5GGihTc5XpJ/99RZxWd8xtXgwzQGGWxgKLztxfjHJs00=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

Latest 30 of 196 download URLs

Remove bitlordsetup.exe - Powered by Reason Core Security