daemon-tools-lite-12708-dp.exe

Kisi

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application daemon-tools-lite-12708-dp.exe, “Kisi Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Sacip   (signed by Mode Beta (Fried Cookie Ltd))

Product:
Kisi

Description:
Kisi Setup

Version:
3.2.2.4

MD5:
7734b3b4c04f888a1f48c6314e1623f3

SHA-1:
3ccf3f94a64778fa3bd8937f32bb779cc5e92794

SHA-256:
b1aaec9d47ec69ed08f04eaf875d6f78c38463b79e04edd014eb1358709a2bf5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/1/2024 8:26:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.4.22.1

File size:
952.6 KB (975,504 bytes)

Product version:
4.4.2

Copyright:
File Lite

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\daemon-tools-lite-12708-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:LjJz9OiMv1hlYlmHZRY5L5H/9x7NJXH6:LlZMb/5RYRV9h36

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file daemon-tools-lite-12708-dp.exe has been seen being distributed by the following 50 URLs.

http://www.cycleupdateguard.com/WVl6OTRQVGxWZEhaTmNURTVablFsTWtZNVdFbENUemNsTWtKcU4ybFlSVWxLZUU5blkwUldWSEZ3UWxwNWVFcHRaVTlSSlRORUptTTlPRlJyUzNkUE5FMDBXa0ZZZWpSbFVqbE5iMkZZU2twalVrVjNWWFI2VGs1WlVqaFNUWHB3YVhVNFpDVXlRbXBTZGpoUFdEY2xNa0l4YUZsaGRuUm5jM2xpYm5kR1dYTlZkVzlsWmxaR1ZXaGtiazVCV2xCM2RUUnJhMWh2U1VwVk0zWlpOelpxU1hOQmREbFZPVWhPTWpZMmJUZzNlVkV4VURoMGVrRlZVWEZZZDJSMmJVdDVZMXBwV2tGa05VZGFVWE5pWm5CMmFWaElaeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVJGUk1hWFJsU1c1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVVJCUlUxUFRpMVViMjlzY3kxTWFYUmxMVEV5TnpBNExXUndMbVY0WlE9PQ==

http://www.capitalsoftwaredownload.com/WVl6OTRQVzVUT1ZwVWFrTlViMVZ6UTFjbE1rSnJiRU1sTWtKS2RXWjBVRFJWYjBKUFZuUlRPQ1V5UmxGemRtUlBja3B1YkRnbE0wUW1ZejFvWW14cFdIbFJUR3B2U0VKaWJUUnlTVU5qYlhJbE1rWjRZM0ZIVDJocVYwMUNlbkJxUlZSak5qUjZkVWxtY2tvMWNuSnJTSEZUT1hvbE1rSWxNa0pCWVc1b1IyOUdTRzVqU25SdmFVbEthM2N6VHpkS2MzSkdWbGwwTTNWYVoxUlNRbU52YUVWWGFHMTFKVEpHYmtsWVNucFFSRTVxTjBSTFMwcG9TR1lsTWtKQ1pFdFZaVmRVU2tkVk5ERkRRWFZqV25KSWJFdE1jRVpLWVdGNlQwcEJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aRVZFeHBkR1ZKYm5OMFlXeHNaWEl1WlhobEptUnZkMjVzYjJGa1FYTTlSRUZGVFU5T0xWUnZiMnh6TFV4cGRHVXRNVEkzTURndFpIQXVaWGhs

http://www.farmtowntowers.com/WVl6OTRQVmxIYWpOU2NVb2xNa1pRZWs1NFFWZEJiRmgzWkhabE9TVXlSbVp6YkVWRWIwTXdZMWhHZUVGSWJHOVpjbGxWSlRORUptTTlTRkpUWTBaQ1JERkxSM1pNZGpKbGVHTndkelZLUkRkMWFURkdjV0Z1Wm1oRE9EUklhbFZSSlRKR0pUSkNNMUVsTWtaRFoxTnVUMkpGUlU1SGRrUkZXbUUxTUVSeFVsbGhiSEpJUzFaTGFIWmlXazAxYmpabmVURlJTMUZ2VWtScGRVMTVWVFZYTlZONGMydzBRbU00WmtWRWVHVk5NMmxHTmxOa05qRk9ibGRUVFZGd2QxUkJXR0pQYVVJelZsQnJOV3RPVVVaMVlXSjJiekpCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWkVWRXhwZEdWSmJuTjBZV3hzWlhJdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UkVGRlRVOU9MVlJ2YjJ4ekxVeHBkR1V0TVRJM01EZ3RaSEF1WlhobA==

http://www.laboratorysafehead.com/WVl6OTRQU1V5UW1wekpUSkNha05ZYlhKcmNEazROMjBsTWtJMlUxRnFibVYyYVU5c0pUSkdiR01sTWtaRFNuaEhSVEJhVEhrMFlVTlpKVE5FSm1NOVZFSlFVazlJVERka1lsY2xNa0pSU2s5aFJuaDBhVVp0VHpGeFpUSmFWRkI0U2xGamIwNGxNa1pYTlhZMllUQk5OeVV5UWtKNk9YUk1UMGhIUWpKQ1kzbFBWVUYxYTBWWFQxWnpabGhhTjBjeFdsUjVXbEJQTkRSRFVqWnJVVTh4V1dVeGFuTklZVEZCTUZBbE1rSkpTMU1sTWtZeVNIbzVRbk51VG1nbE1rWkpWbVUzVVRoT1VXWjRhRmRLVGtOTGVHNDJkV2hrSlRKQ1NIVTVZMUUzYm1veFlYY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmtSVVRHbDBaVWx1YzNSaGJHeGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MUVRVVZOVDA0dFZHOXZiSE10VEdsMFpTMHhNamN3T0Mxa2NDNWxlR1U9

http://www.capitalsoftwaredownload.com/WVl6OTRQVkI2VFhKTE0wWXljbEJ5WkhadlUwSTJTazlVYkZSd1oxcE5PWGw2Ylhwb2JERlNURTVhYm1aRU1WVWxNMFFtWXoxMVkwbDRObFIyYm5oMlVYcFRSRXQxTVhjelZEUlNOVTVqU2pRNFlUWmFObFpqZG1wMWJHRkZaamRRY0dsc2IyMGxNa1kwZGpRNU9EZFJUbVpKUzBaRVVVY2xNa0o0Ym1oc1V5VXlRblJsTkhoc2VtUktlbEZ3UjJkRWIzcExPRXBhVXpONmFGaE5hMUYwUVVSbVlXaGxiV2xvVEZSWlJtZ3lhRU5tTlhaalNYSjBTbXBaZGxSRGF6SktWWFI1SlRKR1VrSjFaVk5FYVVwbVNuTkJaeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVJGUk1hWFJsU1c1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVVJCUlUxUFRpMVViMjlzY3kxTWFYUmxMVEV5TnpBNExXUndMbVY0WlE9PQ==

http://www.capitalsoftwaredownload.com/WVl6OTRQV1ZtVjBKUWNHMUdNRXg0T0UxdFlXSjBSM3BXVjNSdFEyeDZSMGczYWlVeVFtWXpaRkVsTWtZbE1rWkhZV1ZJZVZVbE0wUW1ZejE2WkZGMVVqSk9NM1ZXYzNoMmVtdEdhemhHZWtOdk1sbElUWFJ3T1RRbE1rSmFibEF3UmpobllpVXlRalZVVjFCU2MzRmllRkExZUZOMVIySWxNa1pJVTBKS2FWUWxNa1ppVDNRNWJHZERNREJtTjFkV1FWWWxNa0pHZW5CcFJVRlZhakZIZUZGUVJDVXlRa3htUkhjelJucENWemc0UVVGb1JYTndPSFozUldwNk5sbE5jMDFPU1U5SlUwWm1TVmRRTjBSU1VsQlhjM0JtY25KWFlrRm5lVUVsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYzNSdmNtRm5aUzVrYjJKeVpYQnliMmR5WVcxNUxuQnNKVEptYlhWc2RHbHRaV1JwWVNVeVprUlVUR2wwWlVsdWMzUmhiR3hsY2k1bGVHVW1aRzkzYm14dllXUkJjejFFUVVWTlQwNHRWRzl2YkhNdFRHbDBaUzB4TWpjd09DMWtjQzVsZUdVPQ==

http://www.gifttownsign.com/WVl6OTRQU1V5UWpReWIwaFRXRk5uTXpSRFZXTWxNa0pEWkdjek16UnVlVWhtZEV0WlJrSktUVGRTVkZFbE1rSlhhblZ4Tlc4bE0wUW1ZejF4T1RGMFlVUklRbEpQY1hnNVdsVkxSSGRuZDAwbE1rWlJjWFpPSlRKQ2RFNW1XSEJMVlVaU1QzUkxiSFJSU1U1bWNHRTJWbnBoTTA5amFFZExaRXBMTVVSRGNHdG1TMlEzUnlVeVFtMXNaMjVSUXpGU2MxTkVhM0pqVjBaM1dFSlhNSGx6YkZWeFRXaHFUV014YUUxc01sTnRWMlpPV2tWa01rSlNTR2gzU1ROVUpUSkNWMlJsWjIwNGQybzJRM2N4V0hJMVpTVXlRbTlGWm5oSVltdFJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aRVZFeHBkR1ZKYm5OMFlXeHNaWEl1WlhobEptUnZkMjVzYjJGa1FYTTlSRUZGVFU5T0xWUnZiMnh6TFV4cGRHVXRNVEkzTURndFpIQXVaWGhs

http://www.sharetodaysafe.com/WVl6OTRQVzlqYVUwMFVrbFZSRmRYZEVaV2FuaDBURGRVWW13MGQxQXhVVVZKTTAxMFVrTk9WbmRWU1UxTmJITWxNMFFtWXoxa1VtMWpKVEpHVjFaMU1qUlVSa041YlZwbFlVaGlSSFJSTmxCU2NuQWxNa0pMYldVeU16UktOR0VsTWtaUVpsUnZRMEpXZEU1NFpIaDNWbE00TTA0M1kwOUdSRlJPVTJwUVJGUkZZamhJWlhOT0pUSkNkVkJOYlZNeU1tSlRSbGh1V25nNFZEbEVkRVI2U0dneFdXNHhOa0pwVHpKR05IUmhPV0UxZVV0cVNsTmFiRTFPUm5aVGVtRjJhVFZsVGpKUEpUSkdaalJUZHpJbE1rWkNkRk5qUVdjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbWJYVnNkR2x0WldScFlTVXlaa1JVVEdsMFpVbHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxRVFVVk5UMDR0Vkc5dmJITXRUR2wwWlMweE1qY3dPQzFrY0M1bGVHVT0=

http://www.gifttownsign.com/WVl6OTRQVXhOZDJVNU5GZzRVbnB0Ym5sVmIzZHNNSEZPTjJjM1JISldVbXBCYjBjMWJHRnRZbWhGWkd0dmFsVWxNMFFtWXoxcFRUWnphRUZOUkRsV2JDVXlRbUZIUWtSclVYb3dkbE5uY1dKVFVGRkJjak50YVhFMmRqRnRTbnBqYVdSRU5YVkxOR1pHZEhGVFdWZFRiRFJpZEhwaFpYSmlaRVV3SlRKQ1NrNXNlRWhEY1UxTGIxZDRSQ1V5UmpOR2FXeEJVRTVUZEdkNFZrZ3lVVGR0YW1Oc2FqUklTMmhFWWs1RGVFTmpaamhZV0VWUVlVSmxjRkp2YkVsV1dGSlJSM2hVVFdsRWRXVjZTemszZEhCbE1YY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmtSVVRHbDBaVWx1YzNSaGJHeGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MUVRVVZOVDA0dFZHOXZiSE10VEdsMFpTMHhNamN3T0Mxa2NDNWxlR1U9

http://www.citysafeapplication.com/WVl6OTRQWEpxVW5nNVluaGxOWFlsTWtaTlVWY2xNa0oxYkVFbE1rWjRTVzVaU1hKRk16azNVblYzUVNVeVFsbDNkREJoVHpONFVTVXpSQ1pqUFhjMGEyc3pUbXhvUTJWRlFVeHVWVGN4YURsamQxSXpaSHBsSlRKQ1kxQjJWbGxxZVhWWFlsaEtUbm80V1hkRmFUQlBjVWxyZENVeVFqRkNRemhOY25OelpFa3hURVkwTldJbE1rWllaWGR6Wm1obmVFUm9aMlp3VDJSR1RsYzJSeVV5UW5sVVMwTjVjR0ZZWVhKV1ZGVlZObEZtZUNVeVJtVnNUREpZSlRKR1ozRm9TRVUwTm0xcFVVdDFSRlZDU0VNNFZqaFJWVVZyV1doSk5IVlVPVUphVVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aemRHOXlZV2RsTG1SdlluSmxjSEp2WjNKaGJYa3VjR3dsTW1adGRXeDBhVzFsWkdsaEpUSm1SRlJNYVhSbFNXNXpkR0ZzYkdWeUxtVjRaU1prYjNkdWJHOWhaRUZ6UFVSQlJVMVBUaTFVYjI5c2N5MU1hWFJsTFRFeU56QTRMV1J3TG1WNFpRPT0=

http://www.sharetodaysafe.com/WVl6OTRQV3gzSlRKQ1F6aGlXVFJ2TTI5VmRVMDBaMnMwZUVwNVZqbHZkR05UY1RFM2VrUnRjalJuUjJGT2VFdGxTU1V6UkNaalBVbGtjbU4yYVhCdVVtUlVSMEp5YkRsV2VVb3pkMmRMV1dKcWJETkljRXcwWkU5V1dXWnJZbk5ZZGxWaWVuUmpRalZsYW1oMFozcExZVTk1U1hKU1pWZGtXV0pNYWxoSVVDVXlRalZOYldKb2FEWlVOR3huY0ZodGRFWjVZVFl3YjJwM2FGZDFlaVV5UW5GMlYwSjBaMmsxVWtkSlZ5VXlSbU5JWnlVeVJtdHhVblJwY0dOMmMwVWxNa0l3V0ZwRlUwdHJRV054TkZWblYyZHlTSFpDVkZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbWJYVnNkR2x0WldScFlTVXlaa1JVVEdsMFpVbHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxRVFVVk5UMDR0Vkc5dmJITXRUR2wwWlMweE1qY3dPQzFrY0M1bGVHVT0=

http://www.laboratorysafehead.com/WVl6OTRQVVJCYUhWNGRGbDFkV3hoVDNCMWFVTkdhSE14V205cFJETkJTVEJsWm1nMFZrdzBjVlEyT0ZZeVkxVWxNMFFtWXoxa1dYRXpaMFo0VW1vMFpXdzBRek51TWxSalNHb2xNa1o0VEdvM1VHMUZaRzF4ZDBwVmQybHFhMDRsTWtaM1QwOWxTamRTU21acVpqRkxhWEZXVjBRMldHaDRabVZDV0dOdWNHZE5TalpuT0dGNmQwTWxNa1owTkVKUmVVWlVjV0pWVUhKTE9FTlVjR1lsTWtZM2JFMVFha3d5ZVVSa01FcDVNRTR4YTA1S0pUSkNORlZqY1hOdGNXRktiek0yYjNGblpsaFJOMlJoVVZFell6UTFhRFJCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWkVWRXhwZEdWSmJuTjBZV3hzWlhJdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UkVGRlRVOU9MVlJ2YjJ4ekxVeHBkR1V0TVRJM01EZ3RaSEF1WlhobA==

Latest 30 of 61 download URLs

Remove daemon-tools-lite-12708-dp.exe - Powered by Reason Core Security