codec-pack_installer.exe

Nof

Prompt Funnel (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application codec-pack_installer.exe, “Nof Setup ” by Prompt Funnel (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mimo   (signed by Prompt Funnel (Fried Cookie Ltd))

Product:
Nof

Description:
Nof Setup

Version:
3.2.5.5

MD5:
e7aedd374f0da08dd737eb616f33cb56

SHA-1:
595f368e8738eb9bfe1d9555ab0ce1602920c479

SHA-256:
23c5d96dd11879d39da8984026b3e9c3af46eee46e565c0d24a2b61572e8f9fa

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 5:15:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.19.13

File size:
958.8 KB (981,856 bytes)

Product version:
5.1

Copyright:
Lite web

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\codec-pack_installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/18/2015 12:07:46 AM

Valid to:
5/4/2016 9:27:49 PM

Subject:
CN=Prompt Funnel (Fried Cookie Ltd), O=Prompt Funnel (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219770E5FF2BA80CECD3514AF9CE966758

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:bYbUGa2/HaxL5hLk61i8GjBosouQbUnckP6qcMViNAQ:bLdhLfLXo8sosBncknriNA

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9307

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file codec-pack_installer.exe has been seen being distributed by the following 48 URLs.

http://www.worldrepositoryclear.com/c?x=/x6PtvjvKKMNpRa2KmvxGA/dOKFdqS4DhynkehSHWi4=&c=UxbmC3iGKydzVTOg09JrKMD8mYhfoPx1ifp7qy5UxsSYPcsEELrva4ANxdH77C5IF6xnQkYrcpFZSVr7N2F0X7qo2oS4huKRZ1K2N0dwjyKNJ/grxo/JeFw6DZafuIds&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=Xnx/Rikm2E1pdicn0rCk4URPvIVHGgXsqnUhSvD/V2o=&c=WVPKqHUrN1Dll9h3wme2pgT1/mol9YZGU/NryIVhP DzpuOxpa KOd/NBIiKnACjdWSJxbQFNcyMyLkhXnxjSSHKJQ Q8NBW7EorlGmhmEvMHsMAdII7FdgLYz6SPH29&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=7ojntCRuwH1LUr1F96hXtnDSHWhxRZ87XgvFJREmMs8=&c=Fykwt3HmsH0YDijjzi9cBRzaKz9vDp9zEMhCtRDC/4WlG2YjNKlzt9ewJfMd90fhm0iv4nSFLnc6imrvBHPkRrXmj3eAN17uVtni J3NQfbDTOk2mcXNpk cjFGB6pTy&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=9cbiuRF7OSsnsnc937XfQpUCZvTLzXCjmdGVO4nMK5M=&c=WDcpnhsBw4pnU03enp6xwpKQc1/216BR2VF0hb/TKuzk4xZa2Nq9evXQ6yyv3VKDM2du/5ZB5ksqUVz/L6CpIoRk47ApnyVqbKrChClZ6n92RVPuJ0jV0TOQ8nydQvHj&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=G7A2bCGeWncbKFH7 XFO4 HFz9cXpHlXVfZJt7TnxHs=&c=5Bb66Osi/jSFbnJ0zQIkGO1IlGcQZlsSjM7MOrBJ/bhz9yrEO2UeFOmX5qaIiqw7AuUJMiBS8kmT vnlLcspru2W JBBgMWxJSIpxUHLvGkKLQnIx7Ie01PTHuoNAjYZ&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=ucOJUFKWxLshebik V/FM51WOm/DdIDe7ITJFbRoQ1Y=&c=2Atkgx0antKWK ATj7xpEHzwKmCMXWHkRf sWANjoNxhiWfIzxCgdI/0P iRlRX7/MyNmz6JNAg6fIVRykwLukYI9NMNOAw8TJV4SFsZs12ImomyW6QDmsnjtdO5Yboq&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=NKl72uwbWb7UYpI2A5EdpITETU5V46Ypu8g/IilXi1Y=&c=qvdq3n0p33StQDvFbWwU8o7bmuz/JI43yOe1e1asrzqFQTRstRkl9vgEgE8 Kz1HUssF ORkf2i4HHJSnwBszAclB1usoSg8/Ynz2EoX/xypnIt1Y yCnx/ YMkldOOq&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.worldrepositoryclear.com/c?x=0YCij/hsNNNlHBAfj5pdrmmvIruM0V7gBXYJn vt1x0=&c=J0WWmE07hxpKCXMxvWS4sth1 jis0BtYlvqiujFtbL3IK2CTnHCii1WvHXNVJUHjn5EVcGIA3AjLZZN7FAWsOyqmxWAxEkgpHSCyH3sZ/pmj44a3R4AIkaY38VrhBnk3&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

Latest 30 of 48 download URLs

Remove codec-pack_installer.exe - Powered by Reason Core Security