gimp-13219-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application gimp-13219-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
347543d820d4bef6e629e475b5839a7d

SHA-1:
0fab61eb3990548b63db2d31fc02a6d2d581bb0a

SHA-256:
ada4f599042fd1b35d5cb9f548fd87af2c308bce5b30204cd6d03740ffe47bdf

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 6:58:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.17.17

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\gimp-13219-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:MCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:MrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file gimp-13219-dp.exe has been seen being distributed by the following 14 URLs.

http://www.deliveryheartconecpt.com/WVl6OTRQWEJEZUd4MlpIWTNNMVJCZFcxRE5VcHRiRlJIZEhOUk9ERlRNRzE2YjFkQ2FFSnNKVEpHU0VWS2VtWTRieVV6UkNaalBWYzFWMWRHVEZaVmNWcGlSbkp3V1ROVWEyMWFTVlZZWVc0M2NFZzVlR0ZxYlRWelozTkhPVm94TUdkWFMyMVRSMlZEVVdsa056WlVhMU5MTTIxSlVHMDVRbWRvYzFKbk1WQlhhbGhOVVVsUWNFSnRWbUptT1doS1JVRkplREI1TjNWblltWXlURFZzZVdSemJVRklOMjl2WldNeVZXVmFOa0ptTkZsTVJVSm5TVTVXTUc4elRVUnBkRVpyUzAxckpUSkNVMHhvU0RSUkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVptUnZkMjVzYjJGa0xtZHBiWEF1YjNKbkpUSm1jSFZpSlRKbVoybHRjQ1V5Wm5ZeUxqZ2xNbVozYVc1a2IzZHpKVEptWjJsdGNDMHlMamd1TVRZdGMyVjBkWEF0Tmk1bGVHVW1aRzkzYm14dllXUkJjejFIU1UxUUxURXpNakU1TFdSd0xtVjRaUT09

http://www.funsignssend.com/WVl6OTRQWG80VWtJek5VNVJabVZyVlNVeVJqVlVkbXhaWVhaTFVVWmpNVGRvYVRWTlFsVk9NSGh6ZW5Ka1dGTlBVU1V6UkNaalBWZFpiV1ZyTXpsTVIxbEVWVFpxUmpaTk5YTTNhR1oxVjFFeWNHWlFjRUpLTlVwemJXWmpaSEJWZWxFNFpsUXpVWGMwT0RGTGFEaHliazQwVFZvME9DVXlSa2dsTWtKNlZVaENhVUptU0VjMVRtZFFkV0p0WWxNbE1rSWxNa1pRTW01dldqZzBVMFZRUkZKSGVFTkdWbkJTVlcxcFRXOVBkR3RQVTFoV2FXMHpSek5yVVcxSVlUUTBVMGgwVGtkM1FrWmFjMWszTlVaalNERnFkVlJSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG1kcGJYQXViM0puSlRKbWNIVmlKVEptWjJsdGNDVXlabll5TGpnbE1tWjNhVzVrYjNkekpUSm1aMmx0Y0MweUxqZ3VNVFl0YzJWMGRYQXROaTVsZUdVbVpHOTNibXh2WVdSQmN6MUhTVTFRTFRFek1qRTVMV1J3TG1WNFpRPT0=

http://www.deliveryheartconecpt.com/WVl6OTRQVzFDYmxGbEpUSkNSREpPUTNWbWRHWkdZMFJ6V2pOR1ozZERTbmhQTms4eFptODFhMEZqTjB4cUpUSkdkbnBWSlRORUptTTlSbmhyUkRsemFtNHdRaVV5Um5RNU1EWTFkRWcyVGtRemJ5VXlRbFJCU0RCNFFrTkZRVTl0V1U1RGJXaDFVRXczU0V0aU5FMUhUbmh3Y1RWVmMySTVXVmxCY1hkV2RHcG1iU1V5UWtKRGJYaFZOVWhHYXpBNFNuZEdVbEJDUWpoUlRWY3piVkEyWkNVeVFtdzBaMlU0VjB4alRUQlZha3NsTWtaRE5XMXZkVUV5Y1hWRWFVUmpWSE4yZG1WalNEVkxOVlJCUnprMk4zaHdiVkIyZFZWV2R5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNW5hVzF3TG05eVp5VXlabkIxWWlVeVptZHBiWEFsTW1aMk1pNDRKVEptZDJsdVpHOTNjeVV5Wm1kcGJYQXRNaTQ0TGpFMkxYTmxkSFZ3TFRZdVpYaGxKbVJ2ZDI1c2IyRmtRWE05UjBsTlVDMHhNekl4T1Mxa2NDNWxlR1U9

http://www.vaultschuckleapplication.com/WVl6OTRQWG8zYm5wNFIzUmlTbTFWYlNVeVJuZ3pWMUpCTldGNGRFSkdiVVkxUVVSNFNWTlFhbUYzYWpGekpUSkNNWEIzSlRORUptTTlZalJtWW5selQzZHNOMEZLSlRKR2VIQTFiRE54YzJjMVN6WlFhbTlTWVVsa05HRk9KVEpDUVhoTFpERnNaWEpaYlc1Tk9IRWxNa1k0VjFCTWNtWlVUM1JJT1ZWVFZUTlRUV1I1YzJkR1lXcDNXbGxNVTNwc2QzcGlSRXBEUWxabmVuaG9OM05rVFhSb04ycG5NSGd3YTBscFpXWnZPSEJ2ZUhVbE1rSkNTa0p5Umxsbk4zRlpOV1lsTWtKdU56RmxTRFFsTWtKSGQwRjNVVzVSWVVvM2FIVlJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVJ2ZDI1c2IyRmtMbWRwYlhBdWIzSm5KVEptY0hWaUpUSm1aMmx0Y0NVeVpuWXlMamdsTW1aM2FXNWtiM2R6SlRKbVoybHRjQzB5TGpndU1UWXRjMlYwZFhBdE5pNWxlR1VtWkc5M2JteHZZV1JCY3oxSFNVMVFMVEV6TWpFNUxXUndMbVY0WlE9PQ==

http://www.worlddlstock.com/WVl6OTRQVTQxVjNwa1dsYzVSazVQSlRKR2RXOVNUekpSU2pKVVNrSnlXblowZGxSNE1XZDRNRUoxYkhKdk0yNUdSU1V6UkNaalBVOXVWVXM1ZFVrd2ExbFBhMmhLYlRaNk1VZE1UMWxaWm1sT1FuTmpXbVowV25GcVNTVXlSa1J1Y2toMFFVTXhRV1JzYkdjemF6ZHNaR0U0TUhOQmVuWnlUM05HWkhwRWNtWXdTalF6SlRKR1EyMTRiMDFyTVRBbE1rSWxNa1pYUVVkMlJXNVFRVE15V1RkMVRrbzNXRlJwVkRSV05TVXlRazFWZURSR1dURnBaVEZEV0RKalZGaEZSVkZrVFhGdlJUVnRTWHBVVFhSR2N6QmtUell5WVZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdVoybHRjQzV2Y21jbE1tWndkV0lsTW1abmFXMXdKVEptZGpJdU9DVXlabmRwYm1SdmQzTWxNbVpuYVcxd0xUSXVPQzR4TmkxelpYUjFjQzAyTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVWRKVFZBdE1UTXlNVGt0WkhBdVpYaGw=

Remove gimp-13219-dp.exe - Powered by Reason Core Security