installer_for_cool_edit_pro.exe

Lacodi

KORAM GAMES LIMITED

The application installer_for_cool_edit_pro.exe, “Lacodi Setup ” by KORAM GAMES LIMITED has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.afreecodec.com.
Publisher:
KORAM GAMES LIMITED  (signed and verified)

Product:
Lacodi

Description:
Lacodi Setup

MD5:
de0b9387b90e59fe2d8307414a8b2c04

SHA-1:
7396b9b1bec4a77bf910a4650fcdb39871cf4f2a

SHA-256:
52bc9b0ddb48e410cab513c503c3cb077b9e0a4a8ef17a939ab153f4e34e514c

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/2/2024 3:39:51 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Malware-gen
160518-2

Dr.Web
Detection.Undefined
9.0.1.05190

ESET NOD32
Win32/InstallCore.AGU potentially unwanted application
8.0.319.0

Reason Heuristics
Win32.Generic
16.6.4.17

File size:
997.5 KB (1,021,432 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\installer_for_cool_edit_pro.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/22/2015 12:00:00 AM

Valid to:
2/8/2017 11:59:59 PM

Subject:
CN=KORAM GAMES LIMITED, O=KORAM GAMES LIMITED, L=HongKong, S=HongKong, C=HK

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
7E60950268CB02F219923ADBDE0484E2

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:pVXlBJgKcPOdzbCkvBuZDvZZoftas0bRVcauFVHT:pVVLgbmdzbCkvBuZ1ZGtaBRIVz

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file installer_for_cool_edit_pro.exe has been seen being distributed by the following URL.

Remove installer_for_cool_edit_pro.exe - Powered by Reason Core Security