bitzipper2015setup.exe

Cima

MaxSpeedy (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application bitzipper2015setup.exe, “Cima Setup ” by MaxSpeedy (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
MaxSpeedy (Fried Cookie Ltd.)  (signed and verified)

Product:
Cima

Description:
Cima Setup

MD5:
a6988b48017826e452f3d8a203c031cc

SHA-1:
884f13784671ebab0d5413a8d814dc3365a69fdf

SHA-256:
478814c2b6df19cdbf7502a2a1cc34013c695789f301cf5a35926d38c9394912

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 4:38:14 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.4.3.19

File size:
1 MB (1,094,904 bytes)

Product version:
3.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bitzipper2015setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 3:11:09 PM

Valid to:
6/8/2016 6:06:58 PM

Subject:
CN=MaxSpeedy (Fried Cookie Ltd.), O=MaxSpeedy (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112125C58A41E827F13C76AD2A1D648B8808

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Qp1CHYeefisG65UfjqbPmdk681rpUQ6ZFXjwC0POr3s7Oy:Q7vzfzh22rMk6xQOTwCLSO

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8975

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file bitzipper2015setup.exe has been seen being distributed by the following 50 URLs.

http://www.vaultsbodyvault.com/WVl6OTRQV1pyTlRoM2QwSlRTVTFRWW14T1pWbEVTVFV6WVRnNVZVZE5ia2xrYjJkRlZIVkJSelJaUjJ4elZVRWxNMFFtWXoxWVZuSklXVkZFYlRGUGRYSnlSV1F3UXpCWU4yZHhkMEZ5V0RaWmNrMVlNa3RFVWxoM1NsbENNMXBqVDFkUFVraFdVa2hLUVV0UlFsZG5UbmMxSlRKR2MwWm9VRzV4UkRWQ1pFcDZZMnhFT1ZSR2VXMHlKVEpDU1VGcFJVc3hZMnRVVkRoWGQxbFlNa1ozYUd0ak1sVTNjeVV5UWsxVmMxWWxNa0o1ZEhZbE1rSmllV1JJTkVVM2NrTldRMEUyTlNVeVJuSk1SbEJZWVRaWEpUSkNTbXBzVmxoV1p5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFDYVhSYWFYQndaWEl5TURFMVUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbUpwZEhwcGNIQmxjaTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p1WlhkbGMzUXVaWGhs

http://www.tagpresentbody.com/c?x=lQw9wSxCAFHyrzq7giSXQV4Wp7s/oqZdu gaNN3P/TM=&c=JDa1bxQLWBMzzPH6zJ/ttR7ZXMiR2zn yW3tZCUAOeQbDXMQImktXUf5N qxr8GC6y1CugGowkIy9kpWinUAsWp4YfIyt6BwRycqow0Zi2nR9DAY7GO05dgWFyoVujwCEKmySvd7xDPhxFw0u4/2qaVqWun0zsvV9KAAFCv7exPTSqxn1fFftatUehDPfJqo&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.giftvaultupdate.com/c?x=qDyY90DvkrExMMvYPl4uszDeCdMjBgSFwUNcJwRri6c=&c=2hNhGAxfUnIZH9tvQrXDJE6VykXhZuHdYA0WrrDY98zE5ydm9a50S eW 6BMIwxECA1AVuoJBnBo9DmF8m2hdSDAHrfhcwS0PFZ8O XqD8FMTGCmd4WOm1QrVSSQ1V1OuThgJWjs14J8oDx1jNYy1 15trG8on6aa4tcJrSIXMuqfwxQgTdxpb eFvn oAnN&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.downloadsapptoday.com/WVl6OTRQU1V5UW00d1RXaDJSMU4yTjBKS1lVYzRkVlJqU0hjMVYwRkJaMHh4YzJabFNFbERiMnQ2VTFvMWJVc3lTU1V6UkNaalBYWTJiVmxhSlRKQ1dGWk9hM3B5VlcxR2NWSllPR1kwSlRKR1NuUTVRa3g2WTA1WlJXMDFla2hWWnpWa1JtbEpTMEppSlRKR01pVXlSazFNWVRacldVdE1TSGt6VkZoVVpXZGhOMG8xZWxaUVVHWTRRa1pGWjNka2NqaEhVWEZhZGtOS00yWjFRMjVMVDJ3d2EwZHdZVzlQUldWUGMyMXlibU1sTWtKb1NrSjRNSFpGV0ZseU5sZzRPRVptUlVkaVpFNDFiMVJKVm5WYVpXdDFNMjE0VFhjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlRbWwwV21sd2NHVnlNakF4TlZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5kM2R5NWlhWFI2YVhCd1pYSXVZMjl0SlRKR1pHOTNibXh2WVdSekpUSkdibVYzWlhOMExtVjRaUT09

http://www.megabitscity.com/c?x=H17eHYbVcvWKcWWRD8P DtsnwuznOy53b6AZpcDmKm4=&c=wcFj2MvMdLVfx0ajVi9tUuZi/lsHFPfvoE6d97Kk61zZux0FYcmo/E6oWe555GgXXuubHggE4QRqFvDEaxGpkzxSLgh8YWJKLyBhAy8UwnIIOKXUy1uMW47jWlidnxa9LG4t/lY9a9w3HhORY/6ZTEitmtxZg4Z428kJHLoI Qswq7et2RyfDGKt kj6EySG&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.ranchlaboratorycenter.com/WVl6OTRQVzB3ZVRaUWJtdElaMHc1ZUhOTGNtODRVa3h3T1dWbFR6RmFNVWxxVVhCM1pqUkxUV2xTV1VoSVlWRWxNMFFtWXoxelYwWmllVzh4VjI5eFJFZ3dja1l5ZDBkMFJEbEVWSHBEUkZORVdsaHFSMkppVEZCeVpXNXdZa3MxVm1jbE1rSnZlSFp6ZVhkMVl6VjNVSE01UzFad0pUSkdRa3M1VGtaM2VsTllRbXhRYlRCemRVZHRTemcyWm5jeVNHSlhPSHBzYUc5cVFVVkhTR1ZaZVNVeVFtNXBlVXBvVTNZbE1rSkZKVEpDYTFoWlQwVjNhMDlrUTBacU5YTkhZMVZyUzA1eFp6WmFKVEpHV0ZoblVtRk9Wa1prU0hjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlRbWwwV21sd2NHVnlNakF4TlZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5kM2R5NWlhWFI2YVhCd1pYSXVZMjl0SlRKR1pHOTNibXh2WVdSekpUSkdibVYzWlhOMExtVjRaUT09

http://www.todaycitybyte.com/c?x=OMkvdPYFNzfK02A8g09mUhxXrIVk0mS3r9wpIZPUHIo=&c=/9Wt6S4ZTcRdxuYmiJWaPSa6emC6ZHd4vwLYcJ4FJcjSlPqLnlDi4xhUQCG8hRzVaEjtHoKH44 tUfjeMKCMMHpb3Csp0nrX1ZIHxxYpbsijFHSK4On8tDk9/eaWi3jMKSs7iKwRr6pdmLg98h axc5Tq1KOIrV6EKplxcm4v5cpG12s0G6YU1KIj93A1b5E&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.applaboratoryhosting.com/c?x=l9ZA8xaT4ZxqQ RjGazge3EHIxmfZ HKX5FSDJnDSiA=&c=cjwMW0yG9/o6lVK5xHAbCu2hcuJtd Yx9N57qjEta0b3TOTER3nDJyG3ZQZW1wJaCXooPfZE2hT5qIsqv7Ayf3XessgjA676mmMyXJJ B4gyTRSX6GpLtVEtIfxqtlfZFKtwg6g5opyn3vTlqbetDdB/QTJ1bmR9ATA8tdOlUVO3a0JNmkuPwVTiht8TrMXH&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.tourgiftheart.com/WVl6OTRQVmhoTm1wTE1pVXlRa040YW1kaFFVUnRZWGswYkZkdEpUSkdKVEpHVlNVeVFrVldSVGxVYmt0dVltVlFORkZuZWtwemF5VXpSQ1pqUFRsTlEzcHZkR0l3YWpCRVNXeDZkalZGTjA5RGQyWjZWR0ZVYmtGTWVrdEdaMHRsTmpoeFdtSkRPWEJHVFZabVVXTm1SVlZqZW1GaWJDVXlSbEZEZDBWTWRGY2xNa1pVYlVsYWEwUlVXa0p0ZGpNeU0wSjVZelF6SlRKQ2FISkthek56ZDFWclp6Sm9jek00Y2pCb2RGUnJlR2t4V0dGU09HVlBWa1Z0Vkhad1NHMURPRkZDTUVkUlJscFJTVlZSZG1vNU0ySlJRM2c1ZUdWUVVTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFDYVhSYWFYQndaWEl5TURFMVUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbUpwZEhwcGNIQmxjaTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p1WlhkbGMzUXVaWGhs

http://www.tagbundlespresent.com/c?x=9jCtHr7DV9jaNxpIxayuTFpFXdnMttDhPBTg6aZfD8k=&c=yGhZxL6jyu7m5KW/rRAqDpR4Xh0qfyoRB3nTsYVXzParYEr2UzL94kG5J25YRAYivhqqJH4dBaNJqXonLDcMA5Qnzucm0pZtudP2rDScdaS4QqfhYCWMsLe4iZVJOvN PgUb6GPddKbis30QFH/8bVisHChuFgjPjbdbbR9r rYGODwNF4x/Nrbm9ljpcizg&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

http://www.binariesstockbinaries.com/WVl6OTRQVEZuUWtSeWFtRnllR05DTjFSdkpUSkNTWGhtWWlVeVJtWnpZbFUzT0haNlkwSmxNRll3WXpGblppVXlSbkF5SlRKR1RTVXpSQ1pqUFZwQloxZE1Sa2xYWnpZd1IxWlBOWFJTVG1KUlRqQm9PVkpOZW1jeE5WRjVObFZ4UVd4TFZFZDRWaVV5UWpkalRWVnhXR2xWZG1GR0pUSkNZVEJoU25RMmNFazFlVFVsTWtJNU0yWkhNRXhqTm5kclJFaHpPR3REV2tGblZtRjNWR2w1T0VGUFQzRnNlSGQ0UW1KdmMyNVdaV1EwVnpacGVFeE5kMnhVT1dsekpUSkNWR2hOZWxCWVNUYzBaRk5FZGtnMGNXOUNVa3QzU0RaM04wTm5KVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVKcGRGcHBjSEJsY2pJd01UVlRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWjNkM2N1WW1sMGVtbHdjR1Z5TG1OdmJTVXlSbVJ2ZDI1c2IyRmtjeVV5Um01bGQyVnpkQzVsZUdVPQ==

http://www.clearnewmega.com/WVl6OTRQVTAzWkRsQ1UwODNUMDFaYm14UU5EaGpkVWx0V2xkc1VuWXpZM29sTWtadWRscDVjM0J0UWtSeEpUSkNVSGxuSlRORUptTTlaV2cxWlVwNVpsUlFKVEpDZHpka1ZrZFVNV0ZTTVVOS1JYbGlURGx0WkdWbWRISlZaMnRYVDFNeWF6UktTVlJIV20xV0pUSkdabFIxZDI5dWVVbHpja3BLUTI5bU1pVXlRaVV5Ums5aVkxSkRlRk5TVTFGWFducEVOMnhxU0hvMWRFcDRkMlZKZW5seGVFbE5WelpoUTB4SmNXczFZbkJXZW1KRldGbEhjVFZtYWtNd2FVRndWaVV5UW1SNWVuSndlak56WkZOc1drSnNiR1ZuUWt4clVTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFDYVhSYWFYQndaWEl5TURFMVUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbUpwZEhwcGNIQmxjaTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p1WlhkbGMzUXVaWGhs

http://www.ranchlaboratorycenter.com/WVl6OTRQWFJhUVdOWVFqZHdZWE5DYzJSTVowZ2xNa0o2VmxaNk1uVnZXR3BXVW5NbE1rWTJjRFZuY1dsS1RrZEdNMHhWSlRORUptTTljbEYzYmxGVGNERjVOV2M0VGpaQk4xSkhka2RHWlhvd09WVjJVWFoxT0d0UlNGUlFNakZ1UkcxTVdVTkdWWFZVT1ZCVmNGQlljVGRHWTBSd1VEVjRPWEJ4TUUxMmRXY3paRlJUTlhGbVpEUnhiVGR3UlU5Vk9FVnJkRkJ3YUVGaFpXMTZaVVJKTldKVWNtVlpaVlpLWW5JM2VWVWxNa0pDVjJaWk1IZzRkVzU2Y0ZCUVJXZHRjMXB2UzJKeWRUTndhSEJEVTFsTlVtY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05UW1sMFdtbHdjR1Z5TWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVpYVhSNmFYQndaWEl1WTI5dEpUSkdaRzkzYm14dllXUnpKVEpHYm1WM1pYTjBMbVY0WlE9PQ==

http://www.townhostbyte.com/c?x=KQnV/Kvl10l4ItT hgaOxBywbDgrZbqnxR6YqGLFZ0U=&c=f3PWXb2OlpCcML6XWvQfxpVDNdCTvS40PBbIgzgwfk2NIA9L1aoNfbCkhHA9KvUo4gRbDnB3OLJM1PZqhJH3m qt4KWJVeFmCELa2NX5h9XMOv9pSj1lLItCrtNN7r47fdDymhbzT9Naf7nqvALknD910MSIULFZfPVvoqu5NHYwEbo5lSJRq7JfgIVEBJb&e=0&downloadAs=BitZipper2015Setup.exe&fallback_url=http://www.bitzipper.com/.../newest.exe

Latest 30 of 181 download URLs

Remove bitzipper2015setup.exe - Powered by Reason Core Security