foxit-pdf-reader-7-0-3-916-32-bits.exe

Swift Funnel (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application foxit-pdf-reader-7-0-3-916-32-bits.exe by Swift Funnel (Fried Cookie) has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from d.baixakifiles2.com and multiple other hosts.
Publisher:
Swift Funnel (Fried Cookie Ltd.)  (signed and verified)

MD5:
98d2388ee8bbb661d6aab98d243d5153

SHA-1:
0fbc6660ed268ce0b6346e51875ef1e217c4b9f6

SHA-256:
26cf3b1ddabb7320cea93069359fe196a1a03cdb6e4ba069d12aedfa1cfdd25a

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 2:44:06 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.184.126

ESET NOD32
Win32/InstallCore.RO (variant)
8.10708

VIPRE Antivirus
InstallCore
34712

File size:
698.9 KB (715,672 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\foxit-pdf-reader-7-0-3-916-32-bits.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/4/2014 3:05:02 PM

Valid to:
11/5/2015 3:05:02 PM

Subject:
CN=Swift Funnel (Fried Cookie Ltd.), O=Swift Funnel (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219222B1C3CFE5BB71BCB5117BC2A44FC6

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:PT2aBIZBhDJLKc7NlZ2llDPkRZ1PZZrspGqNUHUBxvrQkgEm/XFjwHXwAbd2yZR0:PT2YIlw2yDMRdZrxqNyUB5rQkklwHvbK

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file foxit-pdf-reader-7-0-3-916-32-bits.exe has been seen being distributed by the following 2 URLs.

Remove foxit-pdf-reader-7-0-3-916-32-bits.exe - Powered by Reason Core Security