converterlite-1611.exe

Kemulaf

Beta Setup (Alpha Criteria Ltd.)

The application converterlite-1611.exe, “Kemulaf Setup ” by Beta Setup (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.packagerepositorypackage.com and multiple other hosts.
Publisher:
Beta Setup (Alpha Criteria Ltd.)  (signed and verified)

Product:
Kemulaf

Description:
Kemulaf Setup

Version:
4.0.5.5

MD5:
a434b17136579f4dde96e7cb64b5e204

SHA-1:
fb6e4fba2d970d35a6569e1e789088a59facded9

SHA-256:
10c858fdd61b027539377ce77d58de8ff86ba0fdaa3d43f9dede8ea7d770b568

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 7:21:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.7.7.15

File size:
947.1 KB (969,864 bytes)

Product version:
4.0.4

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\converterlite-1611.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 5:05:12 AM

Valid to:
7/27/2016 11:04:14 AM

Subject:
CN=Beta Setup (Alpha Criteria Ltd.), O=Beta Setup (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121DBA9CC399DC1BEE2669DA6FF3ACD5A4E

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:umiYVeWr1yz9xU1DVoYer+Fk6xcJ4MkdvuICc:u3CUhx8mYC+FnxbdvuIn

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9324

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file converterlite-1611.exe has been seen being distributed by the following 40 URLs.

http://www.packagerepositorypackage.com/c?x=FSMOzSSkb9WqogOJpClgWYUttS1I1fRRJclsaMHlRxc=&e=0&c=oNgDe 9YQ4jm48QNad0GOyEN4n/WXcp/YE2x/nUESTw/z7t8uRkyRH5U8xMhiWia2upgT/PidLyN0DD0w1M/xmY1I7GpO6eKj9pVT aClClmueLLAGg eW2FaaphKEuoz0yfx4UCzO4xnGaQi 8cfUw0DXm4f7K92S0h5Gb/nGI=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=zZ6QUXNl0UTlaFyM0 6Me772yBT5Fg9zsgGc c sr6Y=&c=cc1J7hycbal6714ZZWYI/EGTvoy4S7m4DvsrcwadYSsVW cu2kY2jj9vkzabw8lekrCkEztj7IBvgSl617Jl97HTKEidxM3rjlN5VQQ3xRRtpMTZad7bR Hj5ycEodhHEqzeH7r3zBTDIklmuX50cJ8VzkL9UQ1HTqFIRnv74WE=&e=0&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=iQT1Pfz5RJbkbGQkekaASAWjqH5/QNDSep0guWHTJdU=&e=0&c=iDCS57oToHlP8y7d/ba3uyq/F4 s9YIaq2yxTu1elB1gh6QCKmYXsUCyOc5/FXCwHiR4XZzwV4HdbXRCx OygEWImOxNTHNh7Q2DOu99QOVYRiASvLcV1u0pxq84ooeMVN4vLvf/xe6d40mMTNMkNbh3FaRC 2 fPro60hGDJk=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=vFUC9mNezodAVGMw pNJqaF1hdrWjjKFuzVn05RL1sY=&e=0&c=J3KWD3311oIg 3 /GFgHKZu3KAM/d9WhpUxRLiKj/sFPwBPOCWpVzlnOUq9RK6KohRCkw2HAG/KfB2an mk30qlsT7m/CRJw5F0w6Wy4UqDPh3TpS8qzenb 3Q QF7qUtrknEphMPZWw skRxRjECNN5jcQvrWrK9KOA 6EzjzU=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=2WmTJWjUBkSJer7cRnPhwQ9bPM 5Jc7r4G1SfzJnAwg=&e=0&c=P0JIdnAcKiGdHF/2vpma6vQ9tPxZrGNhe3FezIpK0bH/71Hr9OFI KU5Mh5NKluSuOD J1Bffgv8X1O/bPtOa8Q2LNb4LMllBpAOfQZz0cpuMX9jnCVeVDxgT1gMydMQPVa8jrl4zbTs4edl15/UWOmLGPa9pyUq6ng/Be CCXQ=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=OWwxFZ RlnFAacTU7No4UvbaHltcAdKlTzl/hSvJ5bs=&e=0&c=r2bGFymiJczK87jMCwFnIhbR4PzlAInhm5/V2RIDdm6bH2ym2AeBpXGcXlxk joKMc ltHdOycZT1bXFpjBlzUzq8ZucR2forInfGEJVHNZ/5BAYYSMBiE8aAG54G08p0nU9CTuLHkynjUjLUJOqALDnIOGevNX5S 432R1Ao9M=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=mqsIzk/VPo3RRGjrSAJWrAr7UKnA YrmQhd8 wa8ysU=&e=0&c=5dRqKIb7tr87ZqrlFxiof/3ISnHydBWkTOffw3Hd42wKOq2ItRa4jGoPjQnAzmyYCQf4O8xspHO ulcc8tCf5hcXkhNwhEczXgzDQPB0NKbTVqLSS5an/8M2juUsycvd4YhINgrL afyzmG9NQXlnTdVuSu3JFKRGHKNJcMMgeo=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=/Z1DmWOp2kIwdPH6CUY8BJIUZeMPhBZhswiZgq5LcFs=&e=0&c=RSgKsOkOKCTXMjJGQKPvSSmMXdVwG 67GChiGGwsbtPHGcTgWt/vc2tRv/SWwq4yKRVw9JJ9Xa89DZO2NlNBjpYep01mXZqfnPXtY vrQhcT FNe8pgCdDqhAR/K2L3qbliHjZulm 3CQhUYX sR68C4ECVzw6/jVHPoUoGKyl8=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=zqKXmDqLlW7nj65MeACFlPOogTcVAmNZw8PeiuhqQY8=&e=0&c=zypLzgjb5ce2trEIgf9yRyc brr2uyxPOBp6qBZLSHWu3FZZxj92Hzq1Nna F8WFg MI97ONtHvFNK1Qb XSl1tro81p Wy72ScjdJQ c QC 65v/Yp6PuNruD7/n6UeIsetsIbHwuhbFhaVxvq7uuGVa7fuIffcWWeFjNsmq5c=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=RlvS7L1WTrxVaV0yM4lY5mA5NIV3KtZoL5VO/Sl XZM=&e=0&c=FgNor 6sUHcFSGr1y0ocUvKnjMABliyAuhNKU9hmeo8z1P7UOSHdViFCFSZMTKx5uMCvIj 1ebT9Kd14XnXFC32BZAk4AsydGjTd0SYtWVYxMrV2 uolWmdZg8W MEbC/duciYhfo0046lI7MaJjQD8SmX4O7H0/toeukGQuXdc=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

http://www.packagerepositorypackage.com/c?x=kvM90thyupAsM36bz5V9htz7X4wjyet0cN2Rg7E3xNI=&e=0&c=AjeeT6jxmr9dKBAsI3ech2W025UVXYEkFY Iwe9rERAz g0SHdXOnvmL5EziGa/k2ycqRrSXM tl1eHijQjcUEufhQa8BLS FQNzsIaEPg7Tg6dERYzJj1sAjDBMnRPAJs/ugQWgPx4nFWxcBSc31K9NKsIOkLpDGagnTAobuAc=&downloadAs=ConverterLite-1611.exe&fallback_url=http://.../setup-converterlite-1.6.11.0-silent.exe

Latest 30 of 40 download URLs

Remove converterlite-1611.exe - Powered by Reason Core Security