installer_whatsapp___bluestacks_0190202640.exe

Kutikud

FunnelOpti (Alpha Criteria Ltd.)

The application installer_whatsapp___bluestacks_0190202640.exe, “Kutikud Setup ” by FunnelOpti (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.sendchucklebulk.com and multiple other hosts.
Publisher:
Beremiled   (signed by FunnelOpti (Alpha Criteria Ltd.))

Product:
Kutikud

Description:
Kutikud Setup

MD5:
589e7b97d29995f3623ee69d26f3e3b7

SHA-1:
e49b10f8975feb7888b190220f10b8c68fd97beb

SHA-256:
0fbba6a2426f05a497b5718aa258a2198ca54fa0ff9aef6c97c7483f04197a4a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 6:03:58 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.11.5

File size:
936.2 KB (958,656 bytes)

Product version:
1.8

Copyright:
Wizard Internet

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\installer_whatsapp___bluestacks_0190202640.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 8:41:21 AM

Valid to:
8/26/2016 11:34:53 AM

Subject:
CN=FunnelOpti (Alpha Criteria Ltd.), O=FunnelOpti (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121C57D0836DF0829F54F07ADA2D08AAFCB

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:kAk0HIDTJOC8Rw8jElWnO9STAqzI8fC2sIt:kDMYL4w8jcWOX4C2sq

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file installer_whatsapp___bluestacks_0190202640.exe has been seen being distributed by the following 3 URLs.

http://www.sendchucklebulk.com/rGHoTY7DA3KLdGG6biE2gtGVZgI7QEjRuychgJh dnkxHI54EKuC0yx On9R7XmmKjq18U6oPXmzI8W0r60xwSmSef a0 TW9Gwo8anXclQ_xnSUh4lBjPR4QA3i2kcEgkaOaXAeiNFKbi60vpl17BbJKBjvxYXG_ZpCmtlWDC7b2l3JXWwSCQ1A6NbyNFaf OGETg24qpehhsz4ffk3ioRKh00XMt9qiW2J_GLeiAFg22YUhuuT07vRg2iPYFpjDVrdrksedtGzfe3HaMxxjVuLiU6uW9m1haiatIDo9ZUNrYCLw9ufNC0wejgIguAJmxZ1IW3ot3bbrG3hC6Qa_G2f7il8AJ8WBMjkMhR7riG_Z7R1t1aWgdSUbFmc7hG_jt4cQRBO_1oYbt8KWHlMDHFr868IiZxee6wlV2cVuWMvlo8ciyBD8GDOlq5b5soEGVsBqTwEgYyUKlLIUm4xZa HW31x_jemwj2FDwuW_ruOIQ4zQCkVwZTNU3JbICUYP1f6cITKa9MUDmC_OIJKNiaJ9o1OW9JpRi8qDPb5f_pMxQwVTBH1v54wpjk4yB0FZ0gHQpRC6uJf0JN7MX5ehcz5FuuMcPewz6qh V5rmeIyVuwPQpjzLPWGMyceorETlh 8ggsRwxw65sm1QQbtXJj0x9wpGiDiQ5umEA1OCGJtH DsjgP2i_6S5Qu2n6Ivc3hXCdIBxMaF6nPWIMRWPcUGhQUvDzzBJaWJusk4VxL4J1_s3QQDb60P xd5sRTGzqpZ7js0j4_KZLnKxG7L4grQOllmsn_OfFJqKxX7Qm7q16EO7lXV5Mni1gOocE2qDmS0BvPk5YhZmFPnIO37u6If7IlT4e GYYG8YUq7C6LvXEbnuXWo2HaCtRGyXNSFxXueE734Ht3k5EPkW9uj1 O9IHAG8HrpdMC7opre5v89d4qA2 urCe8ZHLN3D_bI5uAjwKGcl

http://www.sendchucklebulk.com/EkpCURajBpdBDvzQ_9Kd3ccDZVPlWjZv dFSHrslCALWay2FIYwHcEsNhHX9Z3aNLw 50tmVZrWLYLXGWI 4A43nRAQjQXsK6uvwLp5OfOpY_wG3aoRGUPo1WUb5RvMaR2bz0Y_O5MmvDsYZoVeluTZUUhzrzRNmucT097W z3OuEWRrST0vDCiHIKyYJ_uyIgWjJJycO60cbC0CsIxK5nUXy0G50KWzMpmCyV26BJo8yPJHVV7Yb dpEcyfam3Lg3UgWeDBMmRBBFiFlG G5ag95gd9huoUBni03NgYeZM0pyPMGJCy2B90bQRfgC3LWHoKxfSQIAjUFMOkY26OPjvdnKZzmn8S0fpGjdUAavXVkeN0KYsAEaXsgjmY k9vYsE80NRccFkDe kMKtG3KBRFRuYyxLvKmLE9eFTXfjFYKhWkRtXvDmbQnUSj3qLimHOnHDIP9EPYpXsEMdAXmV3jp8XyvkT38keKAf1G_QkHKqGrptrPUwORellMkaiI5n2pWqMLD7j9aThWJAOAZo5ZvCd2eMnMNRlGYl0mvBPJlneAh1IELjwYJe19uMMvD_s4 Omq69YDcrWCdFNZGYvBYDwJRa6bVMHSaKZy8dThWAcUuNgVx9BhdL8zF4jyu_llcEEsxdessNwRx kS4HJbnhVoSUJgO_fpdAre5FBTRkKD3T1i4gFm8EZ8myhtQ93M_DNW8aPxiQB9VYddz4T5O5K9FeusNf7SucaM6rWMxtdUHHUe23XGqFcxHhVH T4ZHhRURC12nvHvip1ism0d7waVzTttm4yjJdsxINw cfulSeOS5JqZhUFra6nS0v5cYsCJ5k6iuPvw7oLjeBgOiw2V8WK1MG_LcH1OKYeFS EE55uZ5CoXeYT3z9zveC6cCU N4w1FcvWUnhH1JMzCvjy6t06t2r Ek6Jv9EEFWjWPQdi9jpO_l0YB49Ri_4OKvFE2f