bitlordsetup.exe

Dafa

House of Life

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application bitlordsetup.exe, “Dafa Setup ” by House of Life has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.cleanchucklemeta.com and multiple other hosts.
Publisher:
House of Life  (signed and verified)

Product:
Dafa

Description:
Dafa Setup

MD5:
863f116085c91eab2160c77dcb4894f4

SHA-1:
b6f0d86e0e1a85f3659d2bf060eeec2a5dd9314d

SHA-256:
d267770877323e6ddbd3d3b8fc0ce5d599a43aa8b78087ff4324bd8803ca1c3b

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/17/2024 1:25:48 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.HouseofL.Installer (M)
16.5.4.23

File size:
1001.7 KB (1,025,776 bytes)

Product version:
5.7

Copyright:
Software installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\bitlordsetup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/11/2016 3:00:00 AM

Valid to:
4/12/2017 2:59:59 AM

Subject:
CN=House of Life, OU=IT, O=House of Life, L=Sogndal, S=Sogndal, C=NO

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0E8FFE1E4086A8FB13C069E8E8571F82

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:KygcPbjgBOAzUY1kYVeCN3o+cqCqDybbvP6nuL6IEf947l0vP+:K5VBVTVeCN4078ucEVtP+

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9220

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file bitlordsetup.exe has been seen being distributed by the following 50 URLs.

http://www.cleanchucklemeta.com/WVl6OTRQVE5NWTBWeFoyOVZjemwwTW5wb1VGQndRbmtsTWtaUGIxcGthVEo1VVdsQ00ySkVkSGwxY2pCcVpXOVpUU1V6UkNaalBXdEJkMVFsTWtZM2RFcDFNbFJPWkVkSWNFb3lTVkpyWVVWaVFuRnJjaVV5Um5jMFJUaGpTRkJNYW5Zd0pUSkNRemhLYjNOWVRsRmtPVFU1Ym5KSE4zaDZjRkUyUlU5aVowTkJaVk0xYkZrNVdXOTZXVUZPWVRjMk9GVkhVRllsTWtKWk5YVkdRa1JpTVVWc0pUSkNiRlo0YkVaeU1GUk9jbFJrY2poQ1dEazJaV1pWVWxST1NtZHBNR3htYzNwMmVFZElVbU41YW5WaVRuZDBWbXhGTlZFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlRbWwwYkc5eVpGTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVpYVhSc2IzSmtMbU52YlNVeVJuZHBibVJ2ZDNNbE1rWkNhWFJNYjNKa1UyVjBkWEF1WlhobA==

http://www.cleanchucklemeta.com/c?x=tajfUSpHBC0VtdufOkL8nkiqCBKsZWm76zkft7m0qy0=&c=5fnEwug6R6bwKB1uMatu7BoTao9SvOzxu0bzfRq39/TJBskHUOVg8rqzKEbAbb9PgdWnz 1xMX4ucrjGbX2m4TYHSl4epsT941MlgrP7WSM0y1hLlHRpVSwYKAcAWPj4WR/p2alKGLoLwVq5xxx6i7pRCtfMJ5IfMq0hsyGg5D0=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=IwODzbvvE1b0xXwCZr2Z6DswrvDmvLgfUpTzG 2TO3I=&c=pjPXsZH9NHZpDQbkYGmUWVYxSKiPzbpwB2zwoJISQ5a7MUVhGliNPOQivzLGtK1m70ssctFyep0T2h5NCBQNeey7lliB95JYHO1JIz05d4QCctOd9Fykqj2Vruc1nXwnlmzmfvmJ0V0apaUrQyI3Q 2FvnsNrWygZuTeNX jWYU=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/WVl6OTRQVGd5YlVscGRuaG9SVElsTWtJbE1rSlRhRWhHWm14S2RHMVdaVlJoYjJJbE1rSnhKVEpDT0dsbVZtSmxRMWhhVXpjMU1DVXpSQ1pqUFdKamRIbFJUblpXU3lVeVFqRlJaemh6VTFaSVZVVllOblIzVlVGamNtbzViQ1V5UmtSQldXZENRVTV0WXprMGNtOVdSMjVxU1U5VlNXRlpkRlJ6ZDJjMlozQkJNSGxMZGxobkpUSkNZVlozVG5KM01FcGpTR0ZRTVhsQ01qUTFSRVJhZFdsbEpUSkNVRzlaTlZseldXOHdVMjFsZUZoTE9XdHZXbFYyYzNobWJXSTBia3BvUjNFbVpHOTNibXh2WVdSQmN6MUNhWFJzYjNKa1UyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbUpwZEd4dmNtUXVZMjl0SlRKR2QybHVaRzkzY3lVeVJrSnBkRXh2Y21SVFpYUjFjQzVsZUdVPQ==

http://www.cleanchucklemeta.com/c?x=//LOdyp97V50VVErf7QyyqN9qlOSqs2DmZQA4znlzsg=&c=ZWorqOxWBqIvivPuNpqYD0wsm6lBg9KgM8FYtUO2QqxKPj3aXP3BDp3a9kQ Ihp/g41n/ AU81Wzt2OJ3J76bdNLGBSJxhUHoWhS8hAnQuEGOiv3Tnul7VQb3naBcmE7e5DuME1kd0rfxIdvcN l6 /1ZLlN0F1A6xJ0nwH d7E=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=K UhYpTrv2KbDC vJLkrIoMthfYgTrhMCccQDYXq/0s=&c=0FiXBK6UANsEAiiJKUTBk3WvNlHdWpvJ2Sab5yMiI1YRPWyCk1eUV14/3 NnMf5AdVYwK 03pZ1lvPCflRCQrbKDXcMhRp4TYpaqSJA1DJIPz0Sxx7bIbMWdhq6szHXB/tqscaKsp738WKwwDmgrSrG9q1jk8z4HxIAnnOXcaKg=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=dwpFCRQVMklJ6Z/p yv14s6nN8hYvfDfSyKXTUkhrV0=&c=J7QkxjYlyRrl1GPhUnVAR3oTNDENQ71/dBJBtPAcIJjBlsvKJSO/dbq1XsEx6p3Q/b9OWYaumiSKOO 1/M7mRXqxjg2A6u8WI68vip1/uDFeI7rbfuA xVYtNemW1LQPNZdveonkvANe1cUAlAY1uFobJm6m9sm jYnIvwYvaneeFtW/4zmC 42jZMhr/YKB&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=0A/zbHZD qmXIpCMAI6WFEO6LYzn44HBfTynNDBH9Bg=&c=9x08 OEf7EWk0D0z4tW03TMUbxxVIUKuvxbezghGyGa5gZUH57MnCMiV82zb3ZqD2WImFLIuFTSGwOToNxEAGLQsAECn4zgnlUk0lU3ryl4n8P8hNfPa4wLd1u9JanaqPQEIpR2aTuPgRpDUFG/gRvHOm3xhPSR8BHFV81grOQFRPiB5uEb742JzaJKuDEC5&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=460tSS/aVli7iFG5gpsP4i9BKRN pGrLwBKxCdZWboA=&c=kxxrz3fnEugwwnmSQyDS74PouNr32jYTdzHgrDS8uDwDJOLK/YW792Pec6yhkdNC0/Usi9G6IfRqBhUap DclaPrRtj4a 8i5dwUpPZQ9lwFloZPxk9OVneaXkNwB6ARkWyikvQt15stJB3diIi2YJb6Mt7A s/Yb/rTWVKSdc8gHBS8e4YPJ8Xn0/7BgDFC&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=SMHfyZYJRQ9SJJF hR4Iq1YHM1EbiI61Araz9inBl9o=&c=Rg07oBJWFdLE3Es tuCVCaOPVLxGMj1n2mqHbx5XI9c8ko9eI43PyZaTv3HkOeUmQBM4snUn8nY6zQ dDX7zgfdlozqqXK7/3g5V/TSRvJtK/Ds94wDMoeKAW2RtBWIDBrD9KqHCTrkVIpU/qMhmon3sJuJ2kowNwkAnaa41jJ4=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=artJotIEi6WdivaytXygZ7sH4mZbYPpxhR4Y/qIeiiE=&c=QGnbt2mRZ0vkDJ3yH8jjoPHOdZntNodS/isG8UPUiappnWHRBgocIlgSpqopetojxd9jgW3GbzZMzpsYuNqwCjLCsP4kCmE9elFhPlPlbNbGydeRNvBEmV4tZuj9poNJhNGJrajMx72mMP8bma0QGuSiQ6AvfEkNi56RKT47g6pl23O67fR HLCqv35ToFtn&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=8bpEGJaKCti9fj8RgR2hMDRumJ2l/y7A5mEleCHQgAg=&c=pZ9P1qHNdFveJpEkpIwN4yG58ND1ElimuaH6iGsdrt5O/XttFdmgw0zavyPddbT27tqGQ0tcqdoWYNSU1 1G9hcW8czbjw4wHZ/pKvWAThsLbFcuSEPHsmaRssgSlgBQYDnqmN zmX70aWyfFMoJOew65YGQXVdegLKWOuX9R0qXdSYACsm671CQ2IKhwPuG&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=4sMMehR8zEvr1Eurj/Zmo9MfEyx3Gja6ZTxjlHXJsw8=&c=9dkcxpau c5iheZDKxVGJSUzOQ0swdFsaXFzqC1 paxLVmDDehwdLSaBi0FCJ9CSJy65wituNNyj5iz4DDVqbRfO7OfxpFl59b4y/qKu4mBJUEgEtSBJfSM0nqOj53p2t102kqVfFfr7HZeJrjuqmLFlm9ug0lbdhO64ejBaB1NVonanH3mt4tqR1aE0aCcy&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=mo0Yz3Y2ac1jORPVnpY2X2ut4K1kgyCrpuCv5/Wl5YM=&c=1ltJVORLmaTbEjLLWRM6BgG6kPuuSMo4ijv/oiw0ay2ezLamdW5BOm3kz8kVgvYioENPi7iY9LCg50UfyuGOIwAbxWJA2hZ8ob0ldJVLO4u7tgT1db7LZ8XNN9TSi0e1mKzp4dCn30mJGyx8CNSCwThymJH auYGEjbKEJqNIRI=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=WJnNTLA9u7mh/VRNlKMbDYtemjs1SBLui6hsWg5Gc4M=&c=8pGfWUnaemDQQwydoor0YVN5XAVM/pPy/Md5HekGUIa3q v7jqP/DuDhGbW9J3F263oMFk YC1KxPBwjPAon1lvKxB8lNM34j g9E8xw7cbn2QS9DWQHxBxsbVjqWw 3GUyTWuqwM6awd1lr4WjOEmS5jj4ViZP10UbXRramS3Y=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

http://www.cleanchucklemeta.com/c?x=eKhzsaV72Zgd NP0I62t5yPchlEc9FWRkHCBum6FPQo=&c=HBDLeiFcqgGkYCuHYI5WBOLnrEBlXZH4DQ00JMymx5YVEmcPVd17ncLY2Xahu3oD0x7sNcfw3LZRt7JlQPAHwaGI2O5QLcYTaHbff1kl DrjFTLXvHnPW9ENplnT/6a6bCnwN9bucCAEEB2cKhJ9VDMsdSh76EVS6u6OO/BNKew=&e=0&downloadAs=BitlordSetup.exe&fallback_url=http://www.bitlord.com/.../BitLordSetup.exe

Latest 30 of 136 download URLs

Remove bitlordsetup.exe - Powered by Reason Core Security