counter-strike-global-offensive.exe

Bilocideh

SpeedyPrompt (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application counter-strike-global-offensive.exe, “Bilocideh Setup ” by SpeedyPrompt (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
SpeedyPrompt (Fried Cookie Ltd)  (signed and verified)

Product:
Bilocideh

Description:
Bilocideh Setup

Version:
1.3.4.5

MD5:
3d0e58b882fc253cea580150141d1011

SHA-1:
05cb95412c9dc24a2acca7edb5e061ca4d3a59bd

SHA-256:
873712c27cba299e1af7cc2175a791f2d1167f15a1ca13dac31fde37a0626a20

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 10:33:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.16.22

File size:
940.1 KB (962,688 bytes)

Product version:
3.8.9

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\counter-strike-global-offensive.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 4:03:52 PM

Valid to:
5/20/2016 7:07:50 PM

Subject:
CN=SpeedyPrompt (Fried Cookie Ltd), O=SpeedyPrompt (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D77437A5B286B055B435AA59CB4BA265

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:MTZ/UNmp+F6Y/taNJPjYhVyP+a+8cMVTQAl/8nXoaY7Ab1a5Fnh2IUIjmm0ESlXL:MTZcQpqwJPP+a6IXUgAb1aXhxUT7lV

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file counter-strike-global-offensive.exe has been seen being distributed by the following 50 URLs.

http://www.downloadsbundleranch.com/WVl6OTRQV2RvVG1KamVVMXNka3B3ZGtnNVNtaHdWa2x3Vlc1aWVEWnZTbmxQUW1KdFIzWnRhbkUyWlhneEpUSkNjeVV6UkNaalBUaG9WRkZ6Vm5CcFl5VXlRbGsyUmpodGFGY2xNa0o2TkVzM2RWTkJjeVV5UmxZMFFucDRZVUZzUVhScFUwdENVMmw0UVdrNVVWVlBTSGhZSlRKQ1JqVXdaVmxWTVVSNmRreHZTVkprYWt0dmRucFNkRlozWVhsT1ZrbDNNSGhETkdGclRtaExKVEpHTkRoeGMyaERlVlJTT1ZoVU1XaHpTVTR5YjBWWlpGUWxNa0phVFVJMGRUaEpZa0pZWkdVbE1rSkRjV1ZqZUVsYWFHaGxRbGx5VmpWR1dFTlJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p6WldOMWNtVXVhVzV1YjJSc0xtTnZiU1V5UmxWVEpUSkdZMjkxYm5SbGNpMXpkSEpwYTJVdFoyeHZZbUZzTFc5bVptVnVjMmwyWlM1dGMya2xNMFp6ZENVelJERkNiM1Z1ZUdaSE9EZ3pTMDF2WWxWR1FuRTVkbmNsTWpabEpUTkVNVFEyTXpRNU16Z3lOaVprYjNkdWJHOWhaRUZ6UFdOdmRXNTBaWEl0YzNSeWFXdGxMV2RzYjJKaGJDMXZabVpsYm5OcGRtVXVaWGhs

http://www.quicktowndl.com/WVl6OTRQVWxCVkVvMFJGTmFWVU5sU1RVemVWVTJWSE4xVEVOUFlqUlBUMjVEUm1OblJqaHhjRTlTYlNVeVJqWmxWU1V6UkNaalBWazVWV1oyWlRob2VtcDZhazB5UW1OQ09GbERjbTVsWm0xVVNWaDBTME5pTTNCblFYQkZaVUoxWWt0QlFUUm5XVzA0VEhkT1NVRkZOVnB3YzJ0amVFZFRhR1IxVUd4U1ZFbzRXWFlsTWtJMWIxbFBPRzQwVlVkaFFYcHNhV3R0UVhrNWEwTkZOa00zWWtkTVlWSmlhR1JwVGxGSU1qaHBjR2hoVDBsUE9VczFhR1J0SlRKQ1RYVlBRMk4wWWpSVWRHNVNSMlJ1YzFoclpsRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6UVNVeVJpVXlSbk5sWTNWeVpTNXBibTV2Wkd3dVkyOXRKVEpHVlZNbE1rWmpiM1Z1ZEdWeUxYTjBjbWxyWlMxbmJHOWlZV3d0YjJabVpXNXphWFpsTG0xemFTVXpSbk4wSlRORVJqYzFWMUo0Y1Zwbk1uQndjM1ZxVFhGWmQwazRaeVV5Tm1VbE0wUXhORFl6TmpjeU1qUTVKbVJ2ZDI1c2IyRmtRWE05WTI5MWJuUmxjaTF6ZEhKcGEyVXRaMnh2WW1Gc0xXOW1abVZ1YzJsMlpTNWxlR1U9

http://www.quicktowndl.com/c?x=LdQINXS/w8rIhIeBYjVJXaSP7ef0GYgkLUggcqCfXho=&c=15S57HplM6eb1ug5Hxc32mGWJ1ObhlgN1XTfbrltNp/W6gE8AYnD2eQnHQs8ClwspfEbs02F1A98PC6fPUpkxAHl8A1CfO0IUTTE6OEiVn/ZDlyKZqtM5yieNgd8aEOxoKvamXnuJL6 6F/WSWiuPJZiLyfC4/AuiqkyDzwsNWCmvHz1JGnkIz8ZkW1COcGL&e=0&fallback_url=https://secure.innodl.com/.../counter-strike-global-offensive.msi

http://www.quicktowndl.com/WVl6OTRQV3RpWmtGd1VqUjVSWE0xZUVRbE1rWnJUa2xLVFRGblJrTmhTV2RRV0RoU1ZGWlRkWFZPVUdsTlYzTlRkeVV6UkNaalBWSTRkMGhPZFd0UFlYTXpibkpZZWtnbE1rSm9UMVI0U1d0cmRFb3phRzF5WWpBeFQzRkxORkY0VlV0MVZGQjZWQ1V5UW0xdWNsYzFNbXhDTmsxRkpUSkdiMUZQVkhkVGVtbDFZVUZSWjFoWlpGYzNiSE5DZEZOcFZWWjJVVGM0YWtoVGVsSTJXRE42UzBadVFVWndhMjA0VG5WekpUSkNKVEpHTW5kcU5YSWxNa1poWkcxc1JtOXNjMVZOUVRoQlYxWlVOVUppYlRsblYwMVlZbFY0UkhVelVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQnpKVE5CSlRKR0pUSkdjMlZqZFhKbExtbHVibTlrYkM1amIyMGxNa1pWVXlVeVJtTnZkVzUwWlhJdGMzUnlhV3RsTFdkc2IySmhiQzF2Wm1abGJuTnBkbVV1YlhOcEpUTkdjM1FsTTBReE5FSk1YMkY0Y1RaTFIwTndjVlYwTm5FMk5sUlJKVEkyWlNVelJERTBOalF3TXpRMU5Ua21aRzkzYm14dllXUkJjejFqYjNWdWRHVnlMWE4wY21sclpTMW5iRzlpWVd3dGIyWm1aVzV6YVhabExtVjRaUT09

http://www.quicktowndl.com/c?x=3UHh0fSs9/WXB 6oUjvsnfm6HIBx1abHhMy4 q2K5eg=&c=J22Pj iaxgkT8/Zvg9Hzb6tx/cbsvTI/DTxL5CCCwtqihwiLhKIPMZBT5HvEHtNpjdqb/7g986a2PniBFGA5788oGmBwLYNxbofavlqMtUkGzWig7WcJ0u1YRHBT/vvQJq3lkdVKfd7paZVO5Mq43HLkMEH6/t8jGasmBPKkVe0=&e=0&fallback_url=https://secure.innodl.com/.../counter-strike-global-offensive.msi

http://www.quicktowndl.com/WVl6OTRQU1V5Um5aUGN6QkpkeVV5Um1kc1NVdFlkRVY1UWpsS09GWnhNVTR6Vm1sSGJqaDNieVV5Um5oRE5uaDZNVE00VWtrbE0wUW1ZejFNVTJwVWNuRlRkRGtsTWtKeVZ6ZE9aamhVZWxWWlFYY3dXak5ZZERkb1NWUTJWVFJ4YWtGQlJISjRPVUYyYVRaYVJIRkRKVEpDZERoVk1VNVNWMnRDT1dwT2RtaFFiblJtVlc0MlYwdEViVVJwVVhSV1psWmhhbkZSV0ZKUlYyTllWMnhJWlZaUk5WQkRVR3RzUkVsdmRYWmtkbTE0VXpGdWR6TkxVVm95WkZCMU1VMDRWQ1V5Um1weE5rMDBVeVV5UmtVNGVVcEliRmRMUVV4TVFTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQnpKVE5CSlRKR0pUSkdjMlZqZFhKbExtbHVibTlrYkM1amIyMGxNa1pWVXlVeVJtTnZkVzUwWlhJdGMzUnlhV3RsTFdkc2IySmhiQzF2Wm1abGJuTnBkbVV1YlhOcEpUTkdjM1FsTTBSV1dYWlZZeTFCWjJSNmNURlRZbmh2UzJKUU1VdEJKVEkyWlNVelJERTBOak0yT0RnNE1qTW1aRzkzYm14dllXUkJjejFqYjNWdWRHVnlMWE4wY21sclpTMW5iRzlpWVd3dGIyWm1aVzV6YVhabExtVjRaUT09

http://www.quicktowndl.com/WVl6OTRQVWRSWWpSTVJDVXlSbnBuU20xMlRWWlBUazR5V0ZweGMwSlBjMU53YVdWVk5VbENialZVZWxkVFQyeHVNQ1V6UkNaalBYY3dXbWwyWTNGYU9GaEhWbHBDY1RaSFVtUk1RVXQyYld0a2MweEZVRXBSUmtkS1VEUkxURGhWUlc5UVNGQlJWa1pUZUV3MmQzZDZOV1pKYkRsVU5qSm9Na3AwTTFCQlFuRjNhSG96VFVkb1ZFVWxNa1prSlRKQ05tOXJaRGhyUVc5M1NVdHFOekY2U1dKdVJqUk5ObXBUYkdWTVpHd2xNa0pHU3pRM0pUSkdUbWxITW5wdlJHVjVTelZYV25ScFRsTjVTbVk1WTNkc1ltOVBWVkJSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0wRWxNa1lsTWtaelpXTjFjbVV1YVc1dWIyUnNMbU52YlNVeVJsVlRKVEpHWTI5MWJuUmxjaTF6ZEhKcGEyVXRaMnh2WW1Gc0xXOW1abVZ1YzJsMlpTNXRjMmtsTTBaemRDVXpSRGx0VFY5cFRuWjJZbFZCVUdGR2FtZFFSV2xaVGtFbE1qWmxKVE5FTVRRMk16VTNNemMyTlNaa2IzZHViRzloWkVGelBXTnZkVzUwWlhJdGMzUnlhV3RsTFdkc2IySmhiQzF2Wm1abGJuTnBkbVV1WlhobA==

http://www.quicktowndl.com/WVl6OTRQVXhhWjBsUVFsTklRM0JIWW5SSVN5VXlSbk5wUnpNemFVTnhTMnBYZWxkT1oxWXhUWFZvUTJoTWMwTnlUU1V6UkNaalBYaDNVMFZ0VEdKVlF6Tklaa016SlRKR2REYzVkVzlLVlhOcVNrMUNlamRqYkRVeGFHUkdaMVV3ZFVNd0pUSkNOeVV5UmxVMFZ6bFRlVFZ2Tms1SWJYaFdlSGgzZERacU9FWnpNM1pvVVZoMldFMW9UMmRZTlhwclUydHFVVVJ2VmtoS2IxRkpWRkF3T1dKdVRXWlBjQ1V5Um5sSU55VXlRa2gyTTJwaFNXNW5iV1poYURsWU1XeDBKVEpDT1dsWU5qRnNKVEpDZG5KTU9DVXlRazkySlRKR1RYQnVNbEJHVVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhCekpUTkJKVEpHSlRKR2MyVmpkWEpsTG1sdWJtOWtiQzVqYjIwbE1rWlZVeVV5Um1OdmRXNTBaWEl0YzNSeWFXdGxMV2RzYjJKaGJDMXZabVpsYm5OcGRtVXViWE5wSlROR2MzUWxNMFJMVUdsQ1NGbzFSemxLU0cwNVNqWXhiRnB2V1hWM0pUSTJaU1V6UkRFME5qTTROakV6TlRrbVpHOTNibXh2WVdSQmN6MWpiM1Z1ZEdWeUxYTjBjbWxyWlMxbmJHOWlZV3d0YjJabVpXNXphWFpsTG1WNFpRPT0=

http://www.quicktowndl.com/c?x=k1Uj3l76fMVJs4rJoz/xbsokHueOznXNtdFr2ikqft0=&c=oNyATDDuhi2CJuTruURtdps7xJ7OPzSS7cGtWe91RvCD6zwPzdnT0G/wrBFqAUIdT YrSiUacVxuOI1TpOnEZQKwmj6DFMKKhZmny4g0ILcc56eiOStfiu8vm4o QnwB oWJns8mnv5phrx3NnVFE/RlAkEhWb5/W166y IGkSo=&e=0&fallback_url=https://secure.innodl.com/.../counter-strike-global-offensive.msi

http://www.quicktowndl.com/WVl6OTRQV0ZZWWsxUUpUSkNjMlpwVFRWUmNIbG5OWE42ZW0wbE1rWjBibWxzY0hweWNsZGlPV3d3TTBkVVdqSklSSFZaSlRORUptTTlTRlp1WkRaT0pUSkdhakF6SlRKR1dqQk9hSG9sTWtaRlJDVXlRa1ZGYnpnNWRYVWxNa0pKZUVsTGMzRnZRMDFwSlRKR2FXdFZSVmxOVmtzelVreEVUbEZpVUVwU1RFa3pTRWRFTVVSRFVtTXpUbHBsUnpSb2RGbFlRWFpVYWs5dlJUVkdUeVV5UmxKMGIzTnBkM2RoZGxsM1JHNDFiVmhDWW1WV1JqUm1Vbk01ZUZGc1RWTm1XQ1V5UmtKRFYzWkxVaVV5UW5GSmIySjJTR1IzVUVaRU1FcG9kRVIwYlhCM0pUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNITWxNMEVsTWtZbE1rWnpaV04xY21VdWFXNXViMlJzTG1OdmJTVXlSbFZUSlRKR1kyOTFiblJsY2kxemRISnBhMlV0WjJ4dlltRnNMVzltWm1WdWMybDJaUzV0YzJrbE0wWnpkQ1V6UkZWV00weE9hVkEyTW1vMFpEVlljRnBzTVdGNExYY2xNalpsSlRORU1UUTJOREF6TURrNE15WmtiM2R1Ykc5aFpFRnpQV052ZFc1MFpYSXRjM1J5YVd0bExXZHNiMkpoYkMxdlptWmxibk5wZG1VdVpYaGw=

http://www.quicktowndl.com/WVl6OTRQVk4zV2t0TlNYRnJWVElsTWtad2FuSnlTVEZyYzFGU1VrUlhlR1JrTUVVNFRuTnBUakZZVUZCMWRWUklRU1V6UkNaalBXSnFaVTkzYlU5SU5HcFZORUUzT1RaRmNVbE1SMUl3VVdkSlMzQjBNRTk2VGtjemFqZzBjbXBCUmtOVGNscG9SbFIwVUhoek1rMW5jMU5tUlROYVRXVnBkakpQWjJaWlpFaDBkMDA0VTIxRE1XeDJKVEpHWWlVeVJuQnBPWFkySlRKQ1NsUmpRVkFsTWtKalQzVk9PWGRXZUdKRmFYZFRURXhNZVVKU2FDVXlSaVV5Um1KYWFFb3pkWEJyY25wdlNXRllabmxRZFdacWNHTm5RMDlpSlRKQ1JtUkJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p6WldOMWNtVXVhVzV1YjJSc0xtTnZiU1V5UmxWVEpUSkdZMjkxYm5SbGNpMXpkSEpwYTJVdFoyeHZZbUZzTFc5bVptVnVjMmwyWlM1dGMya2xNMFp6ZENVelJIaFRlV1Z5ZFZCcVl6WmpXbVF3Vkc0NE9YaGtjVUVsTWpabEpUTkVNVFEyTXpjMU16QTJOeVprYjNkdWJHOWhaRUZ6UFdOdmRXNTBaWEl0YzNSeWFXdGxMV2RzYjJKaGJDMXZabVpsYm5OcGRtVXVaWGhs

http://www.quicktowndl.com/WVl6OTRQV1JFTm1WbFJ6RXpiMkptZUNVeVFtaHFjVnBtYTFoaFZIQmpWalpJZDNZemMxaE1jbXhaV0hKM2MyUlROQ1V6UkNaalBTVXlRa2hUTUVoNlIwdDNaWHBEZWxkSFRHTkJabEJXV1cxNFZ6QkJNRXhUYURacmEzVm1ZVGxTU2tscFRUVnpXVkk1YXpKTlJVNXZlbGhtVm14WWJtaExUV2gyZVd0R1YzVjVRMWhRSlRKR1FXNUhVMmxEUmlVeVFtbE5jMkZJUWtwelYxVjFVbGd3ZFZkVFIzaERkM1owUmlVeVJsaEViVFJISlRKQ2VsWXhZeVV5Um5KbmMydDBjR1J5TjBVeVNVUndKVEpHTTNSMVNqZzRXbGdsTWtJd1psZG9OV2NsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVelFTVXlSaVV5Um5ObFkzVnlaUzVwYm01dlpHd3VZMjl0SlRKR1ZWTWxNa1pqYjNWdWRHVnlMWE4wY21sclpTMW5iRzlpWVd3dGIyWm1aVzV6YVhabExtMXphU1V6Um5OMEpUTkVObGxqWkcxT1QxWTFiR2hHTFZSMU1FdDFSSGx1UVNVeU5tVWxNMFF4TkRZek5qWXpNREl3Sm1SdmQyNXNiMkZrUVhNOVkyOTFiblJsY2kxemRISnBhMlV0WjJ4dlltRnNMVzltWm1WdWMybDJaUzVsZUdVPQ==

Latest 30 of 110 download URLs

Remove counter-strike-global-offensive.exe - Powered by Reason Core Security