internet download manager 5.11installer.exe

Cotomo

Delivery Superb (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application internet download manager 5.11installer.exe, “Cotomo Setup ” by Delivery Superb (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Rekuh   (signed by Delivery Superb (Fried Cookie Ltd.))

Product:
Cotomo

Description:
Cotomo Setup

MD5:
1dfeb421fe948cf8a6d32050073ae0e3

SHA-1:
17e18105d90cbb761b542158a099cd4450b09764

SHA-256:
30c0a9b42cf7511dd687d502f38b6226bc7bfcc11d372cf341154b9a79dfa26b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 2:33:20 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.3.9.14

File size:
1 MB (1,095,304 bytes)

Product version:
3.7.0

Copyright:
Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\internet download manager 5.11installer.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 3:59:53 AM

Valid to:
6/22/2016 7:54:14 AM

Subject:
CN=Delivery Superb (Fried Cookie Ltd.), O=Delivery Superb (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211DDE033C8F24FD358ED7B6271AD4DE2B

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:/FZU3XXiniuUEvBzuIaL7YRctEKm2nZsD16TGgug9VCyuVadqc:/FG3XSniVdL7jtEKT8166n4UuEc

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9054

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file internet download manager 5.11installer.exe has been seen being distributed by the following 50 URLs.

http://www.bestcleanshare.com/WVl6OTRQU1V5UmpBelZFNU1iRnBTZUNVeVFsUTJOblZGVWpCMk9GWmhVazlIVlRBeU1ERjFkRGN3VjNST1pIVkhiV2d3SlRORUptTTlOWEpFVkhJbE1rWlVlVzBsTWtKcWIzaFJZWGQyZUVsQ2R6Tk5RMEU0YWxCclZXMW1aR3BJYjA5bllURkxlbFJRTmxoSVNtSlFWRTE1WWtKWEpUSkdPVVpoWW1oR2VXMTZTa3hEVFc5Q00wRm1PWFJFTUhaSVVqbHdORTlpTlRaRE5UZzNSRXR1UjJONGRuVjZRM2RNTVhaNlRsVkpWMWh6ZDI5dVV5VXlSbllsTWtabVkydDFURmxqUVhSb2FEVlFWbkZPVm1ONlVGTm1jekZzUzNSYVVTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.bestcleanshare.com/WVl6OTRQV2RGVEVSVFl6bHRPSHBYVEVjek1IcE1hR3hrV0ZGd2JXeHBSMGxxU1hSTmVIQlBhekF5Y2lVeVJrRnRheVV6UkNaalBXdFFZVTlqUW5OVWRqUnhaa1JZV0hocU5XSkRlVWRCWXpVeFdXUmhUR3hUY0hKUWQzTk9lbFZHVmpoUFFVWldTRVZ3VWtKQllucDNKVEpHVUdOaVZuSk9VV2hwV2treVJFbGxOR2RvZEhkUVR6QjNWVEExUTJweVZFVlFSRXBUVjBweWRXcG9iRlJ4TlhSTlNFTnBZVkJZZUV4R1ZsQkNNR1JoWlVWRWF6QndlV0lsTWtaa2NYTkpNV2w2U1hkV1FYZHVTa1F3WVZwWWFsRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05U1c1MFpYSnVaWFFyUkc5M2JteHZZV1FyVFdGdVlXZGxjaXMxTGpFeFNXNXpkR0ZzYkdWeUxtVjRaU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6UVNVeVJpVXlSbTFwY25KdmNqSXVhVzUwWlhKdVpYUmtiM2R1Ykc5aFpHMWhibUZuWlhJdVkyOXRKVEpHYVdSdFlXNDJNakJpZFdsc1pESXVaWGhs

http://www.bitsguardtoday.com/WVl6OTRQVkZ2ZG5aM1JHOU1ZbU5qU0ZBd2NYVkpaWHBVYm14elRtVlBjMWRLWTJWbEpUSkNUR0U0UmtSbE0xbDZaeVV6UkNaalBWWTRSbTl5ZFdSUk5pVXlRbE5oYlVJeVJWcEhVMFJJTWxSbkpUSkdhMmRuYTFGMWNFNXhhbXRzYVVwT2VWRkZUekE0Y1c1cFEzQlFkaVV5UmpWWWNqQXdWVWhsVmpJbE1rWnhSalZGY2pCaGJrNVhNRVJOZWtwcFRXc3pUVEV4TURjd04yeHdkbmhLWlZGMlFqVkphMGxKZERkeFN6RjVKVEpHV1NVeVJteG9PRGRpTVVGb2EwTlhXVmhPZW5CRlVYWlZSak5zZEZwNU5tMXpVR2wwTlhwQlVTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.conceptsgiftrepository.com/WVl6OTRQV1ZGY201clJtY3hUM1J5T0hKaUpUSkdTbGxtYUhkYVFqaEhjMGhGWjNrbE1rSnZTRzAzZURsNmJuWnNkMVE0SlRORUptTTlObEJQZVUxcE4xUlZUVE5xU2toeWRHOWplVlYwV2xKVWJ5VXlRak5RY1ZadmNFY3hVa2hUZW1zbE1rSTJWMWxKYlRSemExSnVjR3RUY1hwSFMwWlBaMEp5TjBkd05rdGFOVzFvVm5GMGJISnVkalkwYVNVeVJtMXFSVGMzT0RrNVpteGpVRmh3Vms5R1QxazRSVlJxV0daT1RVUjRlVEpTTm5GdVJqVXpSM3BRUVhaQ2FqTTRjbFpzTWpnd1JEWnRTMEpFYldabGFDVXlSbXhzSlRKQ1p5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFKYm5SbGNtNWxkQ3RFYjNkdWJHOWhaQ3ROWVc1aFoyVnlLelV1TVRGSmJuTjBZV3hzWlhJdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdiV2x5Y205eU1pNXBiblJsY201bGRHUnZkMjVzYjJGa2JXRnVZV2RsY2k1amIyMGxNa1pwWkcxaGJqWXlNR0oxYVd4a01pNWxlR1U9

http://www.conceptsgiftrepository.com/WVl6OTRQV0l3UTBsUVVXaDJaR0ZETVZacmFUbG5VRkJtU1dKU1REaDRlV1pXTjFwcVJFWmtUV3B0WjNJNVYzTWxNMFFtWXoxdldFSkZSRlZaYkdaNFRrODBXWGsxY1ZKaGJIcDFUVkZYVWlVeVFtSnBkSEY1T0cxT01rNW5RMDVQWjFaV1ZXY2xNa0pwU2xKTVJsbFBhMFpUYUU4emNrWXdla2h3WVVWMWNXdEJSVTVMYkRsemVEaEZjMnRaYUhaSE0zUkxlblVsTWtZeWJGbHlOSFJMWjFNNGIwRndieVV5UmtjMFJESnJOR3BLV0VaUmNXZFVlblJOWkRGbWRqWlhNR2NsTWtaRWJHaFdaazl2TlU5QmMyUklSa2hSSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBVbHVkR1Z5Ym1WMEswUnZkMjVzYjJGa0swMWhibUZuWlhJck5TNHhNVWx1YzNSaGJHeGxjaTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtadGFYSnliM0l5TG1sdWRHVnlibVYwWkc5M2JteHZZV1J0WVc1aFoyVnlMbU52YlNVeVJtbGtiV0Z1TmpJd1luVnBiR1F5TG1WNFpRPT0=

http://www.conceptsgiftrepository.com/WVl6OTRQWEZZZUhveFUzWXpVbHBLZDA1cVYyOHhOMnB0YUZseFEwVlNTSEYwVDFSRlRFWk9ZelZKYW05aFVFRWxNMFFtWXoxNFNITkpTU1V5UmtGWGFHTlhWbm96UmtOUFlXWTJaWEJzY0VGNGQzbEpSRlJXSlRKR2FVeDNiSFZ0WVNVeVJrRktjM0UzY2psdVdHZHNVa295VlZaUWRqUmpkMGhQZFRoT1JVZzVNa1ZLZEd0dGJXeERVbFp3ZENVeVFuUmplV1UyTVZGUlZHbHdkRTlEU2lVeVFrUTRRVGhvVmt4MGRGTjNZemN6YmpSQlJYcFBUM2d4VFdoQ1NHMW1VR2QwT1UxMWN6ZzRaVGxMTkZKVFVIaHJXbTVuSlRORUpUTkVKbVU5TUNaa2IzZHViRzloWkVGelBVbHVkR1Z5Ym1WMEswUnZkMjVzYjJGa0swMWhibUZuWlhJck5TNHhNVWx1YzNSaGJHeGxjaTVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtadGFYSnliM0l5TG1sdWRHVnlibVYwWkc5M2JteHZZV1J0WVc1aFoyVnlMbU52YlNVeVJtbGtiV0Z1TmpJd1luVnBiR1F5TG1WNFpRPT0=

http://www.bitsguardtoday.com/WVl6OTRQV1ZyWkhwSldrMW5ZWEJQU2xkcUpUSkdlR05UWjJ0a2VYVkthMlZJTTJWdVJqYzNkekpRT0ZORFNUVm5SU1V6UkNaalBYVjRieVV5UmxSamRqWkRZbE5uWkVJNFlraERjSGhYYkhsVVpITTVKVEpHT1ZoTllWTldWelF4UzAweGRIRmtVbVEzTW5aamJtTlFUWGxqWVUwd2FGSkxVamhhZUd4VUpUSkdjRWw1VUd0dE5qUkNWMGxNU0ZSTlFVeHdNSGRtZUd0TFZIRTRhV1p2YzJ0cGFXUmhPV05IVVhsa1pHVk5VVTFaYjJJeFdVVnNSVkJJY1c1UFpuSWxNa1pYUTBwbGJpVXlSbkZHZG5ob2REUlZaVll5UjFFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlTVzUwWlhKdVpYUXJSRzkzYm14dllXUXJUV0Z1WVdkbGNpczFMakV4U1c1emRHRnNiR1Z5TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtMXBjbkp2Y2pJdWFXNTBaWEp1WlhSa2IzZHViRzloWkcxaGJtRm5aWEl1WTI5dEpUSkdhV1J0WVc0Mk1qQmlkV2xzWkRJdVpYaGw=

http://www.bestcleanshare.com/WVl6OTRQV1ZCYzNCdGRscGpRak54Ukc5QmFrRklaRE5uVjJOYVdHeHFPWHBoTTJzNGREZDRTQ1V5UmpaRldtWnBOQ1V6UkNaalBYaFNWbkp1V21rNGVWQk9Ralk1YWt4aFUxbHVSM1pXZUdwdVExUm5OazFIVFZOdmNITTROMFZoVEcxRlowZEtWREZOSlRKQ2RtWm1WeVV5UWpCV1FrNXZibmhMY0c1YVdVcExWRlpzYTA1cmNFNVhKVEpDVnprekpUSkdiMWRSUTNabVFuVlhTVXRwV21aUkpUSkdRMHhuVUZBbE1rWk1iMGx5VG1abFQwb3ljVEJMVmxwaFp5VXlRbWhZY0hCVWVFMXFjMVZFYVZvbE1rSlJjVmRJTWxWRFJXNWFOMEVsTTBRbE0wUW1aVDB3Sm1SdmQyNXNiMkZrUVhNOVNXNTBaWEp1WlhRclJHOTNibXh2WVdRclRXRnVZV2RsY2lzMUxqRXhTVzV6ZEdGc2JHVnlMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um0xcGNuSnZjakl1YVc1MFpYSnVaWFJrYjNkdWJHOWhaRzFoYm1GblpYSXVZMjl0SlRKR2FXUnRZVzQyTWpCaWRXbHNaREl1WlhobA==

Latest 30 of 114 download URLs

Remove internet download manager 5.11installer.exe - Powered by Reason Core Security