counter strike 1.6 steam 1.6 finalinstaller.exe

Desi

Delivery Superb (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application counter strike 1.6 steam 1.6 finalinstaller.exe, “Desi Setup ” by Delivery Superb (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Delivery Superb (Fried Cookie Ltd.)  (signed and verified)

Product:
Desi

Description:
Desi Setup

Version:
4.6.4.5

MD5:
f88e1156326911e16b35e0db222f3252

SHA-1:
ae5e8004bfeb4f858ee90e8c36bfb6a768321c61

SHA-256:
5ee52cc2c2a35e97f83d82d258db04edee8a720c1fd951838bca88030bc47b62

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 1:47:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.15.19

File size:
1012 KB (1,036,328 bytes)

Product version:
5.0.6

Copyright:
File

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\counter strike 1.6 steam 1.6 finalinstaller.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 12:59:53 PM

Valid to:
6/22/2016 4:54:14 PM

Subject:
CN=Delivery Superb (Fried Cookie Ltd.), O=Delivery Superb (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211DDE033C8F24FD358ED7B6271AD4DE2B

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:O6FDDB2KvTXrIoRRh94ikbePBlt2/x54xC4f4EAwogds4yJd:OIh2KLkelxkiE4FfzAwogdsbd

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file counter strike 1.6 steam 1.6 finalinstaller.exe has been seen being distributed by the following 50 URLs.

http://www.capitalheartlaboratory.com/WVl6OTRQVkZHTUdGT1UzVjRUbEpZU0VOQlNFRkxkV05oZVRoMk1HTmxPRkJqVERBNE9IQTNNVGxRSlRKR2FrOTJZeVV6UkNaalBXZEpVMVZWUTBGT1NEUmFVWGhGVkRWSWJqZzFSR295TVRZeldHZDBiR2htVGpsa1pqUTRXVlp6ZVV4U1NsQTNUMmMwYldoblNrRTVaMFZTYVZWVllUSjNNemxKUkRKd1NrRnNkWFExTW1WdE9WVlVSbXBCZGsxS2FVWm5UMmx3ZEUwMFZrVmpaVkIxSlRKR1ZEUnlSVk5rVjFFelpTVXlSbFkzUVdWb2FXNTRWemhPWVUxbFltMXVRbmd6WkZadGJEZDNRMmcwUVhsVU5WRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05WTI5MWJuUmxjaXR6ZEhKcGEyVXJNUzQyS3lzcmMzUmxZVzByTVM0MksyWnBibUZzU1c1emRHRnNiR1Z5TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuTnZablF1YzNCMFpXTm9jeTVqYjIwbE1rWm1hV3hsY3lVeVJqRTBNRFUxSlRKR01UUXdOVFV0WTI5MWJuUmxjaTF6ZEhKcGEyVXRNVFl0YzNSbFlXMHRNVFl0Wm1sdVlXd3VaWGhs

http://www.capitalheartlaboratory.com/WVl6OTRQWEF5YUdoT2VXSkxSMFpTWjNGVWEweFNWMFJ0VGtRMWNYcE1ialZhUWs1SGIySjJSWEZrUzFoR1owa2xNMFFtWXoxQlQxVmhjMmxuWVVFNVkybFFlWEZFZUNVeVFucDVaak0zUlZOeFEzSjFVRTFvZUZOTGQxb2xNa0pHUVdsaGJsbEJjMHRNZVZFeVlrUmxjMjlIY0VSc2RqSlNRMG8zYmlVeVJucFhVVXRoZDBJbE1rSjZNbUZ1Um1SNGQzZDNja3hpVUdnNGMxRlpNRkJUTmpaWVNFeEtWbmhVVlVaalNrVlRZMmhKYWxadkpUSkNjRXBNUXpaeU5VaDBSbXBKVm1rMlFsSktNVlo0V1ROMVFrY3pjWGhuSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXTnZkVzUwWlhJcmMzUnlhV3RsS3pFdU5pc3JLM04wWldGdEt6RXVOaXRtYVc1aGJFbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p6YjJaMExuTndkR1ZqYUhNdVkyOXRKVEpHWm1sc1pYTWxNa1l4TkRBMU5TVXlSakUwTURVMUxXTnZkVzUwWlhJdGMzUnlhV3RsTFRFMkxYTjBaV0Z0TFRFMkxXWnBibUZzTG1WNFpRPT0=

http://www.capitalheartlaboratory.com/WVl6OTRQVTVrTVVSWFJFTm9TRVpRU1RCUVIwVmhVVE5tU0dNMVpWSlViR1poTUdVd1luWkxRMHAwVW1Ka1dtOGxNMFFtWXoxR09VMDVWMjVwWjB0SVozUnBkMDFYVFVjeFZtTkpNV2hDVFcxV1ZHMXNRVmxWTVhBbE1rSlhiME5xYTJWWU0ydHpUelJ4T1RCWEpUSkdUMmh1YldSSWQxRlhhR0Z6U25sclIyeFdNbUZXV0RkcVV6TTJSMVJIUWt0RU4xaFVhV3A1WWxZM1IyRm5WRkJxZFNVeVJqTnJOMk4yVTBRNU1sVmtNREo2UW5jNU5GSlRaMVZUWkhRMFRHZG1jV1ZuUWtaeVppVXlSaVV5UmxFeFQycHdOSGRCSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBXTnZkVzUwWlhJcmMzUnlhV3RsS3pFdU5pc3JLM04wWldGdEt6RXVOaXRtYVc1aGJFbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1p6YjJaMExuTndkR1ZqYUhNdVkyOXRKVEpHWm1sc1pYTWxNa1l4TkRBMU5TVXlSakUwTURVMUxXTnZkVzUwWlhJdGMzUnlhV3RsTFRFMkxYTjBaV0Z0TFRFMkxXWnBibUZzTG1WNFpRPT0=

http://www.capitalheartlaboratory.com/WVl6OTRQVVpCUjJNM2EzbFFUV3R2TkZvNU9GTjViM1ZXVm14eldrOTRkVTlVYmtsM01teE1hM0I2V21sYVFrVWxNMFFtWXoxd1Z6VnhaMlpLSlRKR1pUQlRhbE5EZFhobWQyNVpNRWc0VjNVNE4zWjBiRnA1SlRKR1FtWkxlWG95YTBRNFpreHVkMjlyZUhsSVZrUXpORmhSWTBGSGVVMUhVVXh1Tm1KdFNsRlVSR05CVmtwU1ZuTTJObFYwVDAxak4wSnVTVnBDVTJzd1pVMXBVV3hSWjBSU1lWTnhXamxNYjNSYU0yczRNVUZtTm1JNGIybE5aVWR0YW1aTFl6ZGhTemwxV21adlpURldKVEpHT0dWblFWRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05WTI5MWJuUmxjaXR6ZEhKcGEyVXJNUzQyS3lzcmMzUmxZVzByTVM0MksyWnBibUZzU1c1emRHRnNiR1Z5TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuTnZablF1YzNCMFpXTm9jeTVqYjIwbE1rWm1hV3hsY3lVeVJqRTBNRFUxSlRKR01UUXdOVFV0WTI5MWJuUmxjaTF6ZEhKcGEyVXRNVFl0YzNSbFlXMHRNVFl0Wm1sdVlXd3VaWGhs

http://www.capitalheartlaboratory.com/WVl6OTRQV1ZNUkRoc1V6VnJUa2hyV1c1cldrVkhXa2xIU210RFFXbGtZWEp0VXpSWllYbENWWGMwWkZoSFJsRWxNMFFtWXoxSmFHRmFTbWRGZENVeVJtMUpPRUpYU0hNM1dXeEhKVEpDSlRKR2JTVXlSa2RRTmpoaGFVaHRWRVIyZEhsMFNVaDVUWGszU1ZWdGNGY3pkbVJoVkRkbmJrNW9jVzl6ZGpSWGQzWlNOMVIxVkZrNFNITkhWWGhoTjFWd2RIUkJZbEpzSlRKR1IweFhNakZvTVhKUVdXMU1TV1pZVjAxNVUzQm5WbXQxTUdKclVtbEZRblJwVFdZbE1rSkVkWGh2WkhSRlZESm1NVk50Um5rMlNuTlpXVE4xTW1jbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlZMjkxYm5SbGNpdHpkSEpwYTJVck1TNDJLeXNyYzNSbFlXMHJNUzQySzJacGJtRnNTVzV6ZEdGc2JHVnlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5OdlpuUXVjM0IwWldOb2N5NWpiMjBsTWtabWFXeGxjeVV5UmpFME1EVTFKVEpHTVRRd05UVXRZMjkxYm5SbGNpMXpkSEpwYTJVdE1UWXRjM1JsWVcwdE1UWXRabWx1WVd3dVpYaGw=

http://www.capitalheartlaboratory.com/WVl6OTRQVkp4T1hkMU9FOXZTREZTUVc4NGJsVk5lSGg2Tm5KclUwRldOVFJOT1hkYU5YcHNjMVpSTnpobGJUQWxNMFFtWXoxaWNtdHVPRWhNTUdwd05YQXpTbFZyZDJaS01XYzRaMVZJV2t0YVRsbERjalpWYTJGVmRqSmlNVlZoVjBNeVJsVjZabkpXZDNSd2NGUnBlVTRsTWtKbE5WVXhkbVV6ZGxBNFZYZDNiRzF3YXpkVWJ6QWxNa1pQTTJGVVVESk5jR04zUjBkaGR6aHdSWFZqV20xcFJUWlZRVXQyVUZocmJVMUZaMVp6VkZBMGJsVnRSbTh3WjJwNmRXUTBhM2hKWVdkMlJHbFNUMHd4VkZaQkpUTkVKVE5FSm1VOU1DWmtiM2R1Ykc5aFpFRnpQV052ZFc1MFpYSXJjM1J5YVd0bEt6RXVOaXNySzNOMFpXRnRLekV1Tml0bWFXNWhiRWx1YzNSaGJHeGxjaTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaemIyWjBMbk53ZEdWamFITXVZMjl0SlRKR1ptbHNaWE1sTWtZeE5EQTFOU1V5UmpFME1EVTFMV052ZFc1MFpYSXRjM1J5YVd0bExURTJMWE4wWldGdExURTJMV1pwYm1Gc0xtVjRaUT09

http://www.capitalheartlaboratory.com/WVl6OTRQWFV3SlRKR2FtSTJUbE00UzBWTWNqSTFTMHR4U21zMU9FRlJlbWx1WVhjMWIwbENOU1V5UWpaU2IxUjFZbXhySlRORUptTTlWbWRNU1hOMVFTVXlRbmxRZW00MWVGbERhMVIzZVdreVNtWTBNRUZzTlROWVNVUTBiMVZ3SlRKQ1drbFRlbFJPYldKTVZFRnNZME5YVldsak5XNWxZbVJaVDNBM1JuWkhiblZZTkhNM2QzaERha00xVG5OdFRsaE1WVXRHVW0wMFZuSnBWVzV3ZVRONE9IaHlXR2htVDNaUVduWnBWRzlLV2tGdmNWbDRWbVpoTTB0Q2QwaEhNWEpoY0c1R1dFOXBlR01sTWtKbmRGZ2xNa0k1UVhjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlZMjkxYm5SbGNpdHpkSEpwYTJVck1TNDJLeXNyYzNSbFlXMHJNUzQySzJacGJtRnNTVzV6ZEdGc2JHVnlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5OdlpuUXVjM0IwWldOb2N5NWpiMjBsTWtabWFXeGxjeVV5UmpFME1EVTFKVEpHTVRRd05UVXRZMjkxYm5SbGNpMXpkSEpwYTJVdE1UWXRjM1JsWVcwdE1UWXRabWx1WVd3dVpYaGw=

http://www.capitalheartlaboratory.com/WVl6OTRQVlV4ZEhnNVVHMWlielpaUjFkSE5qTnVOa2xXYkdVM1RWSjBXbkZoTkZjeVpYbFRiRGxwV25rM01uY2xNMFFtWXoweE1XWjNWV3hUV0dZM2JYYzJaa28xWVZNbE1rWlJKVEpHZDFOd2RXMTRlRlp1YmxseGFWZHlXbE5vTmt4Wlp6RkZNMDEwTW5kQlZERjRWRW95TjNaVU1IaE5aVGx0VkdvNVNXNTNhWFJrSlRKR1pWSlhhVVEwVTBkSWRrMVNUbmRZUjJGSGVXUlBhaVV5UW1wT1RrbE9iWGxLV2sxdVdHMHlORWRJYkhCVVExTTVaMVFsTWtKUFRWbzRlakp0U0dOSEpUSkdjV2gzTWlVeVFrazBTRTFJTUhCcFFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFqYjNWdWRHVnlLM04wY21sclpTc3hMallyS3l0emRHVmhiU3N4TGpZclptbHVZV3hKYm5OMFlXeHNaWEl1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2MyOW1kQzV6Y0hSbFkyaHpMbU52YlNVeVJtWnBiR1Z6SlRKR01UUXdOVFVsTWtZeE5EQTFOUzFqYjNWdWRHVnlMWE4wY21sclpTMHhOaTF6ZEdWaGJTMHhOaTFtYVc1aGJDNWxlR1U9

http://www.capitalheartlaboratory.com/WVl6OTRQV3RMYUVKb1NFMTNkVlpNWlhsRGVWRlZXVVZtTkRabFJsVkxSV0pEU25WbVJUSnBjbE5qWkhST1Qwa2xNMFFtWXowM1RIQWxNa1pMVFZacVpIQnlWaVV5UmpOeWNtUXdNMm8wV2paNFVEWnVSVVIyUW5KUVdDVXlSbFJ0SlRKQ2VrSkVORTV3VEVacmNqWmlTbmxFYVZSc2FGTWxNa0pxVFU1cmRWSlNVSEJXTldaNGNUbFNOVkUzV21odFVFdExXRGhoYVdWYVZWVkpRVlEySlRKQ1ZVNWFaemxYUW1kNE5XWjJUWGN5SlRKR1VEZzBNRk4zU21vMWRHSkplazVpZFVwdk9GbHZiWFI2WVdKVlFscG5TalpKZEdreVFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFqYjNWdWRHVnlLM04wY21sclpTc3hMallyS3l0emRHVmhiU3N4TGpZclptbHVZV3hKYm5OMFlXeHNaWEl1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2MyOW1kQzV6Y0hSbFkyaHpMbU52YlNVeVJtWnBiR1Z6SlRKR01UUXdOVFVsTWtZeE5EQTFOUzFqYjNWdWRHVnlMWE4wY21sclpTMHhOaTF6ZEdWaGJTMHhOaTFtYVc1aGJDNWxlR1U9

http://www.capitalheartlaboratory.com/WVl6OTRQV3dsTWtaMWJXNXdVSGcxWkZCclJrUkVhVlI1TWxCQ2RrZzJKVEpHV0Zsc1RubGxXa2t3YzBZbE1rWmtNMUkwTVhNbE0wUW1ZejFFYkZNek5VZFpWalJ1Y2xaUk5IbDBXV0oyV2pWck1YUnpXbXRITW1sblVHRkNlWGRJWlRnNU9XbHBaR3h1Vmt0Q1FuUmpZMDlGZGpsaFZqWnBUbUY0U1VNMFpESjRVMlp6TmpkaWVqaHFVbFU0UW1nMGFVUm9aRzAwWW1RMlNFWnFaRFZQUlRkalIwSWxNa1oyU3poeVMwUnhOM1YwSlRKQ2FYWmlTR2w2VVNVeVFtNU9aWEJ4YjNCbmJGTnZkQ1V5UW10UmEwTkRKVEpHUTJSMWVXaFJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFdOdmRXNTBaWElyYzNSeWFXdGxLekV1TmlzckszTjBaV0Z0S3pFdU5pdG1hVzVoYkVsdWMzUmhiR3hsY2k1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWnpiMlowTG5Od2RHVmphSE11WTI5dEpUSkdabWxzWlhNbE1rWXhOREExTlNVeVJqRTBNRFUxTFdOdmRXNTBaWEl0YzNSeWFXdGxMVEUyTFhOMFpXRnRMVEUyTFdacGJtRnNMbVY0WlE9PQ==

http://www.capitalheartlaboratory.com/WVl6OTRQWGNsTWtKTFRYUmpiVGQyVjFCa1N6VjNTSGg0YlZnMlptMUxKVEpHYTIxWVNFdE1ibUoyT0hGelltRTRNU1V5UWpnbE0wUW1ZejFVTVRKNVZYVTJUbG94VURGWGJIQkVjVlJDWTNWcWRVOXpiazFDSlRKR1N6VXpaRVphSlRKR1ZVdDJTR0VsTWtKRE1uZDVNR1UxZEZFMGRFWTVTMlJNZUdSblZtRXlaRXhYZURkWWMwOTBhU1V5UWtoQ2NEUjRWMFJWZUVOdU0yWlBhM2hoSlRKQ1VVSnVWSGh1Tm5STFpYVkVVa3RwYW5GelNsRnNhbUkxWkdSeloxSXlkRW9sTWtKQ1pTVXlRalJQYm14eEpUSkdObWdsTWtKcmRtTWxNa1pZUjNRM05raDRaeVV6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxamIzVnVkR1Z5SzNOMGNtbHJaU3N4TGpZckt5dHpkR1ZoYlNzeExqWXJabWx1WVd4SmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdjMjltZEM1emNIUmxZMmh6TG1OdmJTVXlSbVpwYkdWekpUSkdNVFF3TlRVbE1rWXhOREExTlMxamIzVnVkR1Z5TFhOMGNtbHJaUzB4TmkxemRHVmhiUzB4TmkxbWFXNWhiQzVsZUdVPQ==

Latest 30 of 120 download URLs