daemon-tools-lite-12708-dp.exe

Kisi

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application daemon-tools-lite-12708-dp.exe, “Kisi Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Sacip   (signed by Mode Beta (Fried Cookie Ltd))

Product:
Kisi

Description:
Kisi Setup

Version:
3.2.2.4

MD5:
5a2062359567a1a0919b1bc48d30445c

SHA-1:
93c0e5d1595f7c5279bfd4b4df526f67ec899d98

SHA-256:
48b465f9e5408ee84416fd1b5b31bc399a534a47fdff11187b29df95d562d1e1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 12:29:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.4.22.2

File size:
952.6 KB (975,504 bytes)

Product version:
4.4.2

Copyright:
File Lite

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\daemon-tools-lite-12708-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:XjJz9OiMv1hlYlmHZRY5L5H/9x7NJXH6:XlZMb/5RYRV9h36

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file daemon-tools-lite-12708-dp.exe has been seen being distributed by the following 50 URLs.

http://www.farmtowntowers.com/WVl6OTRQVTh6VXlVeVJqbDZZbGhET1NVeVJtOVlabXRRZEZwQldISnBhR2MzUXpGNVpGcFNTVmRtT1hrNWJFZ2xNa0kwVDFFbE0wUW1ZejFhVW1vMVlVOTRKVEpHWW1zNVJHeDRiVzFWVW04MldHMUthRmRPT1hkdlZGQlBjbGxYYUc1TGJuQTRSRzlSYlZCT1FUaFpiVlJDV0Rrd2VXbEhaREJVVTNaRFltcHBNVGgxZVVKWVdWQldkVzlwSlRKQ1RXbElhRloxZFhnMk9XaEdZbFYwTUROTlNHNVBjMGtsTWtaTmNrNW5UbTkyYlhaeE9TVXlRbHA0VVhaek5UVldRa0ZRTW1Gd01HNW5NakU1TVVWS09ETkdUMnBCV0RCdVVTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWnRkV3gwYVcxbFpHbGhKVEptUkZSTWFYUmxTVzV6ZEdGc2JHVnlMbVY0WlNaa2IzZHViRzloWkVGelBVUkJSVTFQVGkxVWIyOXNjeTFNYVhSbExURXlOekE0TFdSd0xtVjRaUT09

http://www.conceptsbodysafe.com/WVl6OTRQVGxzUTNNMlFYSkpaMkY2UjI4ME1sUmpkalkwUXpJNFpXRnhPRWxYVkU0bE1rSnNVa0l4UnpGS1lWSkhUU1V6UkNaalBWaFRWbVF4ZDNWb1dYQkxZVzF4YmpGbk1rVktPVnB4ZVU1T1pIcDVWSG80YjBoYVRFTk1SVE53UW1aMUpUSkNNVmNsTWtZelZrSWxNa0pETXpCdlYwMURObVJqUkU1NmQwRkljVTVZVTA4elIxcHFVMlpyTUVORlJrUmtZMkZxUzJ4MlFuVlFiazVqTUZwcGIzVm5NMlJ3V1hVMWVtTnhUVEJVUTFKMU9HZGpUSFpyUTA1M01ubzVKVEpHUlRBbE1rSkViMmN6UVVwT2FubzFZMHh4ZVhjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbWJYVnNkR2x0WldScFlTVXlaa1JVVEdsMFpVbHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxRVFVVk5UMDR0Vkc5dmJITXRUR2wwWlMweE1qY3dPQzFrY0M1bGVHVT0=

http://www.clearguardapplication.com/WVl6OTRQVFpUSlRKQ1ptTkNKVEpHU0d4Q1NqaGllVzlyWlRWbVVFaGFObEJxYVRWWWMyVnpZVU5UYmpSRmRISnZaWGxOSlRORUptTTlhR3hsY25KVkpUSkdUbkpPT0NVeVFqTWxNa0kyTTA5aWVUTXlXazlXYkRoRVVrbGxZM0ZqYUVSWVlrZGpXVUozWW5oWE5EWkVaalZUWkc5cVdqaFlWa0pSUTJZd1ZtRkdXbHAxUVUwMk5IVk5ZV2cwTTJvd1NUTjVSRzFCTkdob1RGQlRZMnN3VUhOM1NtZHdkbE5ZU1NVeVJsVnlhbHBWVEdoTU1FcEVOM0UyVUU1VVdTVXlSa1pRUlZVMWEyVnBkRlpSU201TmN6ZE9kMDVQY2lVeVJuRjNKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aRVZFeHBkR1ZKYm5OMFlXeHNaWEl1WlhobEptUnZkMjVzYjJGa1FYTTlSRUZGVFU5T0xWUnZiMnh6TFV4cGRHVXRNVEkzTURndFpIQXVaWGhs

http://www.sharetodaysafe.com/WVl6OTRQVmwxZWpaT01TVXlRaVV5UW5ab2MyUWxNa0ppTWpnNVR6QlhVbEJhYTBsckpUSkNSRFlsTWtKVFNqbEpjMk1sTWtKdGFqbExRa0VsTTBRbVl6MVFZazVyZUNVeVFtOWhlVFZpWkVOc1ozQnhWamR5WlRaS2NGaG1hekY2TVdWTldVeHRXblF3VFVoUlptbDNVazl3ZWxaSmFHZzVZVU5FYWpob2JHeG5UVGhqV21GSldGZDFWbHBrTTNablpVbzRZamhuYzJkWFREWk5lRWxYUnlVeVJrZ3lXWGd3ZERWc2JFRkVSM1F4TWxGbU5XaERXV280V1ZodmMyWm5OVlZYWVVWaGNHVnRZV3hGSlRKR1dVY3pXblExUjNGbGVUY3haa0VsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYzNSdmNtRm5aUzVrYjJKeVpYQnliMmR5WVcxNUxuQnNKVEptYlhWc2RHbHRaV1JwWVNVeVprUlVUR2wwWlVsdWMzUmhiR3hsY2k1bGVHVW1aRzkzYm14dllXUkJjejFFUVVWTlQwNHRWRzl2YkhNdFRHbDBaUzB4TWpjd09DMWtjQzVsZUdVPQ==

http://www.conceptsbodysafe.com/WVl6OTRQV3h2YlU1M2IwdHNOVGhvYzJwalZYWmtWRGRPY0ZvbE1rSTBRa3R6WkZsTFYxcGFORE5tTlVOUFVFRmtNQ1V6UkNaalBYWjZkV3RqVGxneVJHcFRTRUZTSlRKR2RXbENXVVZFTkRSQk56ZzRWamRwYjNkUFNtUllNVlpIUkdnMWRYRXlWMjFzTkVwQ1lYSnNiMnM1V25WSmIxbG5kRlpVYUhWdlIwdHFjelUwTTFwTk9WbFZNbTVQU0VkT1drTnBiR1pCUmtaR05FVjBRWHByYkhJeWVUa2xNa0pUV1VoWWNGb2xNa0pKTURoV05IRm5RVEZqZEVrd1FqVm9TRE54TlZOaVNsRjRaREJzZFRCNVRFdGFVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVJGUk1hWFJsU1c1emRHRnNiR1Z5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVVJCUlUxUFRpMVViMjlzY3kxTWFYUmxMVEV5TnpBNExXUndMbVY0WlE9PQ==

http://www.clearguardapplication.com/WVl6OTRQVWxoVm1oclJtSndaM2h0SlRKQ1JrOXVZVkppTTJwVFpGcHZkbEpxTWxWVVF5VXlSbGx2TTAxUU15VXlSbEZRY2tVbE0wUW1ZejE0Vkd0WWRrVndiMDFFVmxGTE9XMTFRMDlDVFd4MWJYcEtRWGNsTWtKNlZuZEhObFZRU0V0TlNrMGxNa0kwUkhSbGFGYzRlbTB4ZUVjd2JWRk5XRkZsUVV4dFdsbEJSR3hOY2xSc0pUSkNjVWw0ZWlVeVFrNWpjMFZvUlZZbE1rWlRhRGRtUVNVeVFrRkhKVEpHUlhVNFEyNVZKVEpHYmtWM2FHZFljV3gxUWtkcE5FRXhWMU0yYjBGMFpUZEJObEJoVkZCMlV6YzRjR1I2YXlVeVJrTkhVa3A2Y1ZKb2RGRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmtSVVRHbDBaVWx1YzNSaGJHeGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MUVRVVZOVDA0dFZHOXZiSE10VEdsMFpTMHhNamN3T0Mxa2NDNWxlR1U9

http://www.farmtowntowers.com/WVl6OTRQWHB6YmtVeGR5VXlRalpsY1V0d1NXZFZOemtsTWtaMU5FNHpUWFpSWW5kcFFtUldNMmxIT1U1SVUweFhja1JuSlRORUptTTlhelZGYkVwMWRuQlhVM29sTWtZNFZFbEtZbmg2V2psa1RWTjBjV2xvTlZaNWFFOUNZMU5DTkZGSFUweEZSV2ROZEdaV1RpVXlRamQ0VkVoUFZsTmtaRTVGZURGRVJDVXlRbGx5WlZZd1drUktTVFo1YlZFd1owMURjbEpOUmxwVlFVaGxVWG94V1ROWE1HMTNVbWxMT0ZKTVIzZzBKVEpHWldWMFJ6RnljMmxFWjJKQ2NWWlFSR1ZvZUV3eVQyWkVSekZrUjJsU1pWUkxhbXhzT0ZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbWJYVnNkR2x0WldScFlTVXlaa1JVVEdsMFpVbHVjM1JoYkd4bGNpNWxlR1VtWkc5M2JteHZZV1JCY3oxRVFVVk5UMDR0Vkc5dmJITXRUR2wwWlMweE1qY3dPQzFrY0M1bGVHVT0=

http://www.farmtowntowers.com/WVl6OTRQWHB1Y0dweWVqRkRNemQxY2sxT2R6TWxNa0pPWkdVbE1rWldaMVp2WkhwUU4xaDVKVEpHVWxaeU0wOUVRemhWTTFrbE0wUW1ZejFEUWtkak4yRXpaMWs0SlRKQ1JXVldZa3AzWVNVeVJrRnlhVXhQYUZSM2FIRnpiMVJXWW5VMFEwMXJjM1ZhYUdwMVpYTkhWbXAwV0V4UlJYZHFhR05YWW5kRVZrcHJOSE15TURRNFJFeFZibTlUT1dWdVpEa2xNa1prUkhSc05sSjFWVVp0ZVRsS2NXaERaMXBwU0hGV1dGSkVXbk5DY0VjeFRVb2xNa1pFV1dWbGNrOVZhV2RSVkRoNlNHbzBla0ZrYjNCRE5HSjJKVEpDVWtvM0pUSkdUVUVsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYzNSdmNtRm5aUzVrYjJKeVpYQnliMmR5WVcxNUxuQnNKVEptYlhWc2RHbHRaV1JwWVNVeVprUlVUR2wwWlVsdWMzUmhiR3hsY2k1bGVHVW1aRzkzYm14dllXUkJjejFFUVVWTlQwNHRWRzl2YkhNdFRHbDBaUzB4TWpjd09DMWtjQzVsZUdVPQ==

http://www.gifttownsign.com/WVl6OTRQVVl3VFZwdVozRnVhVTlqWW1GemVURkljWGh3U0dsUFJqRklTMEpvUm5CTFUxbHlPVnA2U2sxUlFtTWxNMFFtWXowbE1rSjRRVWt5YzNReGRUTldhMVpIY1dkclNFTXpRVzQzYWlVeVJqSldlVlExY201R1ZGQktVbkV5ZEdONWJUSlVUR3MyYjBsNlRuRmFRa3R2Um1GRVpYbEpVRWt5T1U5S2IyVlpWRVoyTVhkamJWTklhRGhVVnpCcldFdFNRMnczVUhGMk5YZDJWRTVUVG5wUlMxTlBOazVMUTBocEpUSkNVa0pJUjBwaWRURTRTMlpPT1hBek5uUkhPRVpyVEhoWGNWZzRUV3RwYjNWR1NVRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmtSVVRHbDBaVWx1YzNSaGJHeGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MUVRVVZOVDA0dFZHOXZiSE10VEdsMFpTMHhNamN3T0Mxa2NDNWxlR1U9

Latest 30 of 109 download URLs

Remove daemon-tools-lite-12708-dp.exe - Powered by Reason Core Security