gta 3installer.exe

Pikir

Delivery Superb (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application gta 3installer.exe, “Pikir Setup ” by Delivery Superb (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Delivery Superb (Fried Cookie Ltd.)  (signed and verified)

Product:
Pikir

Description:
Pikir Setup

Version:
1.1.2.2

MD5:
dcd11d0cfb8959305f15c5c7bab65248

SHA-1:
f0f0394e7597383b0ac50a164c7f9460ef4f2d08

SHA-256:
c3cd0adc1156e627063e4ac9f9394c7a0d24125e96d767d4169acfcf0bf98d82

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 2:15:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.18.13

File size:
1020.5 KB (1,044,952 bytes)

Product version:
1.1.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\gta 3installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 12:59:53 PM

Valid to:
6/22/2016 3:54:14 PM

Subject:
CN=Delivery Superb (Fried Cookie Ltd.), O=Delivery Superb (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211DDE033C8F24FD358ED7B6271AD4DE2B

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:09v/RNi5z1KxAnOj07BVY8RxaiztCl5GLl:09ZNY1oAnOAdVTxaeCle

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9261

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file gta 3installer.exe has been seen being distributed by the following 50 URLs.

http://www.megacapitalgrab.com/WVl6OTRQVkV5TkZwVFJEbFdKVEpHYm00bE1rWkVVR05sYzBSb2JVZFRSblp3V0hkR1dXZFJPRFY0WWpoS09YSndWMFJySlRORUptTTlPRlpNU21sSU1teFNaRWxsSlRKQ2VXRkdla2hrVUZkUVMwSlRkaVV5UmlVeVJrbEtVR2hCV2paQlpqTkdhbTVzYjJZMWVYY3daRmh5YVd3emJGbFlSM05uYlRORk5EQjBRV1pQWldGNFFtczVWRWw2Tm5kM1RXMXpUVkJhZEhOUFJuWTBURTVzTWsxTmJ6TTJjV2hhVUhKNGVubFFNa2hqWnpGelNGZG9KVEpDV25ONFZsZExPVkJGZVhSWVYyRkdkM1Y0Tld4d1dXRWxNa1owUldweFp5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFIVkVFck0wbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdWNtOWphM04wWVhKbllXMWxjeTVqYjIwbE1rWm5kR0VsTWtaa1pXMXZjeVV5Um1kMFlXVmpkSE11ZW1sdw==

http://www.megacapitalgrab.com/WVl6OTRQVk01ZWtzbE1rSXdjRkZ6V0U5NFV6bG1iMHRCYkc1bE0zSjJPWFV3VGpGblFWTjJSRFpFTlhaaU5YZFZjeVV6UkNaalBUSXhTalUzZVVGUk1VVm1iR3h1YjBFeU9VTWxNa1o0Y1RWTU5HaHJkV05JY0ZkNVNFcFJNRWR0WlVsRFZFNXRTM1pCTTJ3M2JtTTJORUo0ZVUxc1EwWTFhRlpqY25FeFFWSklaRzgwWm5WT1VEZG1UV3A2TUhacGRtMWtjblk0WmxwSmNucEJWbGRUYzJsMldWcHdaR1pXVDJNemNrbFNhM05HYXpNM1Myb3hiRGMzVlRrelREWldTMGR5VldaVGJpVXlRakZYYVdOR1JWRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05UjFSQkt6Tkpibk4wWVd4c1pYSXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xuSnZZMnR6ZEdGeVoyRnRaWE11WTI5dEpUSkdaM1JoSlRKR1pHVnRiM01sTWtabmRHRmxZM1J6TG5wcGNBPT0=

http://www.megacapitalgrab.com/c?x=B5/Zg/89DyIvgoiCh1gTWp585lvSrUvjR4nAfQSLMDU=&c=G6pdtuBhcuiEorJRKwTeCqJANq6DGauoom9oh2O7OXbq7rq4rqNSw5LqB27MOmrnysTZ4Edx71QeFHehPwEE3JxHjf7a7l d2QyMq7k6ATuUu2mr91o2UGIUwNS/vzxGplyljZBzuEti2KDGqLM3Xg==&e=0&downloadAs=GTA 3Installer.exe&fallback_url=http://www.rockstargames.com/gta/.../gtaects.zip

http://www.megacapitalgrab.com/WVl6OTRQWEpuVTFKNVVFcDRiazh6VFhsTVVIRk9aVFp1UlZWYWVIRlVNRkpRV0VWblNsbHFOQ1V5UWtwbk1VaE1ZeVV6UkNaalBXTktTekEwUTJKWU9VTnhkV0Z4V0dOVFdFOUxjbWxSV2pOM2QwNXJhRkJoWkhKUFIzbzJXV05yVnpkaWFFRWxNa1pzTlVVemFWUnNjRFUyYVRaVVQzQm5aU1V5UWxvemQwVlBiSGRIZEUxWlpEaHdkMDgxU21kWlYwUjFjbkF4WkZoeVdWTjNiMlEzWjAxeGVubFhhRUZLUVd3NWVVVjZhVWxEWkZkcVV6UmFhbGwzVFdONGJHVkpjMkp2WldWa1ZYTnhPVU5uTlhZbE1rSkhVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxSFZFRXJNMGx1YzNSaGJHeGxjaTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VjbTlqYTNOMFlYSm5ZVzFsY3k1amIyMGxNa1puZEdFbE1rWmtaVzF2Y3lVeVJtZDBZV1ZqZEhNdWVtbHc=

http://www.megacapitalgrab.com/c?x=78z9OJLcfNY0sHFs2r7 feHxBq6cdktoBrXBr i2yL8=&c=/kOcy/0widjxksfuVpv0sp90CnkjGwQJ5GK5e/7U0ELoLptyI37Epln niCrWNMhSU6thVN20szjc47R4O4HrxBabxh81vFU0CS6snkUzqIpu1N5gsmjRafS8tzTQjsPtWzkqofer66F TCaOHhyKYss6OAqHAOX0hos4p3MVxxzt6W1MO1YQvRDy5XEXb7&e=0&downloadAs=GTA 3Installer.exe&fallback_url=http://www.rockstargames.com/gta/.../gtaects.zip

http://www.megacapitalgrab.com/WVl6OTRQVXBvWm05V1UxcDVVM0ozVlRKc1dXNWpiM0ZxT1hoc2NsUlNUV1YzYjFkd0pUSkNTbkJQUzJKNmRHZDJieVV6UkNaalBVTklkRlpIY0VkWU5HdG9aSFpRZDA4eU1tSk1VVGhJVGlVeVJrSm1ialZHWVRKM2QyZHFjemh4YlZCQ09XZFRaVzRsTWtKelQwNVVRVlFsTWtaWEpUSkdPQ1V5UWtaaFVYbHJabGxJVmpJMmRsZHFkbXBLT1dnbE1rWnpUbVpXZWt0cGVYTkhhWEpLVjFKS01XSnRPRVJSWVc1MWJIQnJVRnB1YmxaeFJHVlZhMU5JWXpoSVVrNHhXbXRZTm1ackpUSkdhelZQTVRCSGVHTjNiR3B4ZG5sQ1dYaG5KVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVkVVFTc3pTVzV6ZEdGc2JHVnlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5kM2R5NXliMk5yYzNSaGNtZGhiV1Z6TG1OdmJTVXlSbWQwWVNVeVJtUmxiVzl6SlRKR1ozUmhaV04wY3k1NmFYQT0=

http://www.megacapitalgrab.com/WVl6OTRQVU1sTWtaWldsUlZaeVV5Ums5c1NsRTBNVFUyYW5GaFRuZGlhaVV5UW1aSVVuSWxNa1psUVZaaFFqQmtjMjh4SlRKR2VVTkpKVE5FSm1NOVFscHpTU1V5UWpsRlJrVndWMHRDWWpSSVZXVTFTbVF3YVVzeVIyOXNSV3RHTVc5a1NGZHNXRmxNWW5SWUpUSkNWVGxqWm01WFMwdERkMjl3SlRKR2JYTndlbGh4WlhBek5VSjFRalp5Wm5KNFFYUjVWalpXUW5RNVpTVXlSbTVKWjFFeFZrb3hjbWxtUzA5S1NWVjRNVWhIY25kTFUyWkZjbkpYUjJKU1dIWk9aVlpsU0V4UVJGcE5UMjVYTlRoNVMzRlVXVzl3U0dWcWNscEtkbEVsTTBRbE0wUW1aVDB3Sm1SdmQyNXNiMkZrUVhNOVIxUkJLek5KYm5OMFlXeHNaWEl1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbkp2WTJ0emRHRnlaMkZ0WlhNdVkyOXRKVEpHWjNSaEpUSkdaR1Z0YjNNbE1rWm5kR0ZsWTNSekxucHBjQT09

http://www.megacapitalgrab.com/WVl6OTRQVEYyY2t4NGFEZEpRbkZJWm5KQlFXOVlUemxDUlVweU9EWkVTa3gxWjNWaU0zaHBiMUJsVlZGc1dWVWxNMFFtWXoxbk5ESnVSemcwVkRsU2IwcERaRGs0YkdkcE9USlJiekEyZWtKcmFFSTFPVTVXV0ZCcWVGbEhTbkZqYXpWa2FFTlVRM2Q1V1hKd1N6aE1kalo1VjFwR2FFY3hjSFpWTlVwcEpUSkNRV2RYV1Uxc0pUSkNhMVY1ZUVscWQxcGxja1JOWTJRemVXbDBkVGxsSlRKR1VYb3hNMHNsTWtKUGVUTk1abTlpY1U1Qk5rcDFOVWhJTWpsUk9YTTNabkZGTURKVVowdzVVRUo0ZURSc1dsWlpkeVV6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxSFZFRXJNMGx1YzNSaGJHeGxjaTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VjbTlqYTNOMFlYSm5ZVzFsY3k1amIyMGxNa1puZEdFbE1rWmtaVzF2Y3lVeVJtZDBZV1ZqZEhNdWVtbHc=

http://www.megacapitalgrab.com/WVl6OTRQWGhzU3lVeVFsWTRWV3hrU1hkaVpXNXZZMnd6V1VkUFpIbHVWRE5VTUhwaVVsRXphMFptZEcweFdtZE9SU1V6UkNaalBUbE1OVGw2V0ZGNFFXNTJja0YwTm5sbWEwZzJhR1Y0TjBOVU9HdDJkRE56TVdZbE1rWllaekl5ZWxOeFdDVXlSbTlSYUZOVmJTVXlSbEF5VVhKMFMyeE1SbWRGVjI5dFR6WTRTa1ZXZEVscVQzQjRabFp2T0RSUGJWcHFXR2sxVUVWbWIybEZTMVZCUnpNbE1rWjJWbWR1TWpGbFQzcDBOeVV5Um5wbVNUQmtZVkJHVWt4eldYaFdiV3BKU1VOWWNqVldTRk5XYkhselFtWkVObllsTWtKaVp5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFIVkVFck0wbHVjM1JoYkd4bGNpNWxlR1VtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTBFbE1rWWxNa1ozZDNjdWNtOWphM04wWVhKbllXMWxjeTVqYjIwbE1rWm5kR0VsTWtaa1pXMXZjeVV5Um1kMFlXVmpkSE11ZW1sdw==

Latest 30 of 87 download URLs

Remove gta 3installer.exe - Powered by Reason Core Security