codec-pack_installer.exe

Pulakabot

InstallSpeedy (New Media Holdings Ltd.)

The application codec-pack_installer.exe, “Pulakabot Setup ” by InstallSpeedy (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.capitalcenterdl.com and multiple other hosts.
Publisher:
Mapune   (signed by InstallSpeedy (New Media Holdings Ltd.))

Product:
Pulakabot

Description:
Pulakabot Setup

Version:
5.3.3.8

MD5:
a69a57c06d70b21234f5c93aedfacaf2

SHA-1:
c1b6ccbe2dbdec2a93755420022f46ca87fbe2d6

SHA-256:
6ffc554619acf595f7c7b527049df2472cf15965c2a0d0bce8824eb7997bdacd

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 4:21:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.6.26.9

File size:
942.6 KB (965,224 bytes)

Product version:
4.6.2

Copyright:
File Wizard

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\codec-pack_installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/15/2016 5:40:35 PM

Valid to:
7/11/2017 4:28:33 PM

Subject:
CN=InstallSpeedy (New Media Holdings Ltd.), O=InstallSpeedy (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F59EA8A6B04CAE5E738F6CB09D295BDB

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:f7Olet11LF4R3xeOVD+GSJaFhSWXJQuBIA2rsgTJO+vzmzIEqJ:f7yE1b4DeOMjuhDJpBIlrsgTQPUE

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file codec-pack_installer.exe has been seen being distributed by the following 41 URLs.

http://www.capitalcenterdl.com/c?x=lbuaEVsNj9WEC1vu6B5OTQKB6K0ycK4CAEP6C tEPes=&c=GTW/g5WuySghZh6hqnLYPMAD996sBRd3A30w4EASzcz0aGv9Mo0sEaxcLfPXC7R6ioGzl9lOwZm/UyqH7JTTU5AG2wBvzgyw1xsvAVXwNylWgJjwF0MRLfLl7W9SL6Bw&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=ME7p E3oZaZu1pWByeu/3GYAcmNuOK2b75rrVXwVUlw=&c=/nLfb pDOIu fcgTQOThBfaMel5NRsxaUM/5t4 IBe1YJlrClpZ2lxCd3R/h7V0z/w54aiBTcoARmJCZr/S3FziAcNURyRlxJm/4Hhh0wQfN PvNDA6KBQWWbVcVBVlK&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=/5MP0ueqMCAG GEHmPGpafrmXxG5sEi6gzYFI4iGZZA=&c=naN1zcJJgOnjjo4t/Ntt4Ud NvV5ziskuG8YMlKSs5Sv7Xnq2BTPrelFpf9fDeq01ZCQLxxl20/PPHnrT49mphoF1PCB E3Fjm79oqCjtg6aXtaPpdETXr8zLGVRdZBk&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=MLVfstp0WBwUO4nF y8U U4S8QVoHrjPcfOFy/8o tU=&c=h VB3tVAD/AEskoythlKFFUzDwNctXj2Rs6oBUGduhQqwqFPJMXZsscU8O4gV8HkIay4W75LM1RHCQtxq4Rknp03W6lfbhE MzMIxBfDtbOnv82jDU2NBOyXMnaEJx/m&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=vOD7p6HxB4PYNT7bYQXRqJhkuFv7U7/pMKOmvF0a7mw=&c=1stH3IiXK2bSwdHSkNSf0Hbf1xRY51Os2hGk 6UH9o7yRG6Q3ynqU/j4QtMtcSgP15EBnK4V rFbu8I6RqpWBUBNmCsBjL zU4DfA7QqPSljQT4GsLCsZQGfxMgBSdmA&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=RDC8ri4N90EjP/cGt3867v4Bw9Cj1oM4r6GSIu7HAGo=&c=rF6xk2CIHaow6DT0naSpXdfmwk/mGxTA0DpJymluoTLQtv7Looz /5xIc7QQUGZfF77WHmbystnB/HznMuxoDpy49Un7vM69nYv0/fh5Q9i3y9y41W3yv1y1dqW6ZFGD&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=jP6VT0tgscQkXG5y9fvg PSfheHBlSmxpME6 a18Zi0=&c=tep/9G0g 4dIOqyrpe21NJ2tmAXxfig8kS54rJDDD gBNXVMD39tlWcD96UEH4WT3W5KnXHvkjq/E5J 6BjhmXIQIR89F62aRVkpkiYPPHWoSw 0K1Nx1NlFoJUjiuE0&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=QoZfHY6wPo Ay7JCcqOnpPXCfzMtLTqato3JP2tmsnQ=&c=2cZPDK8w6kdEvCxRIm3wyY2CpDiT5 KUAHAbDgFZ0xLHPWigKBFpz7QXwSWfob1dXT6 J15R9/AKj1rFD4wSMrFZKlFk233NccyQwMll16mpTZMvpnAL3pWCkZuJ3Fc5&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=rPQvHjSPJKL3uBBCbEglkNTE3gy4yYBw4qiBdMmnDl8=&c=OF8UTWDkB/pgYeeB9u7IoVQfS6IaUcg5LdRaQ20Me hWyclqk98XRgXw 0opAk6Hv1ls/af8qwwx7ZfRg1K5rj21wVjuXN3juL vBsluFmqHvsGF9sJAA2fuboW8E9SR&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=rlj/9jjGsX8qIQhrjQJEZgBZFW2IDA56wsih43joGcI=&c=vtq0n9Rb7o0mNvUm9qNVfCmPUpMK2Tq7HFsTGI6pJbisTsFXuA0t88wTSnAJL6a4HQVu0jpUD9cBqf8LDQbHMXPJI4ElHTX47b0pHEkpAFl0s5CBPR6TOYsQ2dUINkfr&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=UgYdUJYmf3xQ6tQ5 pigj0thbFHx535LO61f9B9OV4=&c=v0286TSOw3TcgagJuTCpYpGnIe3j7R9guBdtPE6g35AtEIoIj8KxQNdShbtWhwCfbSH39BN2oGzdVvtw8aBPVlAuDDJSd1trK8NC3l7B8BkOWAoIHhP1jAzKrzRS25Jx&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

http://www.capitalcenterdl.com/c?x=/A6EFyan7XmtFwyx6N89lbNKUscF7xA1OOw2CIQMncE=&c=QnANl4rrf9OPlvU8597cPJQqZ94cQHQXs 9D0EzRcTg1XM jA2xJww2Kdv75Dvtx3ahZmsCO8JTUWl9o4cdHGoPxvOZu WsfNO5bQvSXwXlYYp11rRSnCyGq4kS3ZKN1&downloadAs=Codec-Pack_installer.exe&fallback_url=http://codecking.com/downloads/.../Codec-Pack_installer.exe

Latest 30 of 41 download URLs

Remove codec-pack_installer.exe - Powered by Reason Core Security