five-nights-at-freddys.exe

Rofahodec

Quality Install (Alpha Criteria Ltd.)

The application five-nights-at-freddys.exe, “Rofahodec Setup ” by Quality Install (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.downloadclearbest.com and multiple other hosts.
Publisher:
Henedoho   (signed by Quality Install (Alpha Criteria Ltd.))

Product:
Rofahodec

Description:
Rofahodec Setup

MD5:
57f6260e75c669a39ff80c2ffe4f6811

SHA-1:
177923288ea779d303a27f7d791130dda716d4a0

SHA-256:
50ad7a21c4ea4863e6497479a140648949f7c3f077a16d343902a01ddee7ccdf

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 8:17:01 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.6.27.20

File size:
1007.8 KB (1,032,008 bytes)

Product version:
4.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\five-nights-at-freddys.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 7:14:15 AM

Valid to:
8/4/2016 9:59:05 AM

Subject:
CN=Quality Install (Alpha Criteria Ltd.), O=Quality Install (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121BA484E4C31175E4A844ED055428DEC42

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ybl7mOxyccnc6FUxSRDlmSOwxk2y/30v8pIYW:y5rcnhRDJzF002

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9248

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file five-nights-at-freddys.exe has been seen being distributed by the following 10 URLs.

http://www.downloadclearbest.com/c?x=QdWLohPe66rMarDqi125ixqLQk0TAI/B3klIGirQyQo=&c=X5QJni75DQS73nuSEGtvhC34mi/uKyMt/L46ArV00lYoCOqoZhltDUX8Ps3St6asekBXd46v51VNLzHk5fyWRwZqyYGkHTnYOvHFfqsUnpQgbouB6n/q7T8h0zb1pCQkTJQsXLn49cSWfBnjZMLjkladRMNB5d70MQjFeuz5RME=&e=0&downloadAs=Five-Nights-at-Freddys.exe&fallback_url=http://softdownload3.com/s4m/.../five-nights-at-freddys.exe

http://www.downloadclearbest.com/c?x=zFL6d1lsXd8e zhuJiL5BkyhhC9DnamWahYwXsgJ2pw=&c=w4rV0U1Q5QYeS1q1k9gM/6oYJc6rfAwbB7Xf2U0m pa9UAeaUp907rDkL9FHZ2e99xrVaQlYd3DyRK7kmz9QjkWbettoBV3tHIJ7aqVs2o2 DoEnR1LX5yAHRxwo N0UUuQPEWtBl7zLlvSEUNtCTDvNv9FLVZgF6GZ5YHjY54o=&e=0&downloadAs=Five-Nights-at-Freddys.exe&fallback_url=http://softdownload3.com/s4m/.../five-nights-at-freddys.exe

Remove five-nights-at-freddys.exe - Powered by Reason Core Security