itunes-12-0-1-26-32-bits.exe

Dove Delivery (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application itunes-12-0-1-26-32-bits.exe by Dove Delivery (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as Apple's iTunes but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Dove Delivery (Fried Cookie Ltd.)  (signed and verified)

MD5:
ef521a23ad44a376f01e710e0b3dad24

SHA-1:
1f11d21e164c330f4e05bab4b8c54fb073ff1aca

SHA-256:
f4758a3c48ccb05669e7be72189d4dc8c97e4aa42f3640a96cd178cf695ff9f7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 2:08:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC (M)
16.8.1.18

File size:
698.2 KB (714,952 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\itunes-12-0-1-26-32-bits.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2014 10:19:47 AM

Valid to:
10/23/2015 12:56:22 PM

Subject:
CN=Dove Delivery (Fried Cookie Ltd.), O=Dove Delivery (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112137EAE0964D7E3FEF23473D2D8D216639

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:uDnaOsEPZYdCeZvw7/FGMsHBhXvLBK5E7e7sn4Tuc18W9PkcmY9gx1AalobMWrNM:uDnnsEPjeZvwEMsH3Xv1KO7e64yc18WA

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file itunes-12-0-1-26-32-bits.exe has been seen being distributed by the following 2 URLs.

http://d.baixakifiles2.com/?ic_user_id=9289&data=b/z3LqkfFlbE5WvvS//nk4llmYkAQssXmCgsl4PtyLk2 zk0oMOcamKM8VModOyykA0rxBRRpL1Q9hXK8ltekLVGbPRMJh1P88eh4tb lhvTL3JC5YrkM3wVv8QFr5a2L5FD1lbonZ/EU/lWSXS9uEVSPBnJTxitetXt7HtcKpytiJOsVNyxiHYQR38eIxkrmPCRJxthAOFw7ZuBTrFysBJgwgOF7Dt7FjCV19z/N5vn1 fbH9xr8ABXl3E 2oJe/wtQCQLcvL3Zel1IhTyBMFSEo4gORDcacMIvLhzzPWXFnntu3BldONCxoVPqZCpJOwb5/44pAhiwQYk1jLhIchgj2ehDEfvgoayzjkh A96jyjhmd5QwLVeX2xq0wWUchr/2xreG/ItgUjeRT8k0Z9MQjxo1ThXNnB4tN 1mIMwtwjfM87rx/VNFzNRbSegDhZqYW8Gy5fRzuKb1PgRml1 wGIjZ2vk0eud0JyIi1BcERvHHAoQaaVAT0jasfKp658UvjL9WUK9/Fvtbj5Uted4OS1PsGbk81lz1AWkCXsBHMA R7adg/09HmYKLD6/mVubVs4Jk/jecqdw 7qqITbl/d/tx3tWxxYhyc6Wd8vcOUYOsA66t1b93ICSx3XZMN9fgpMiMit6jjzcMJTyieZFtMNOOcFwkJuNcaDUmif8KmK9xzvQBeTPnVDUS16V0hoJDr47H&key=h2c1/LpWs2EdXaPsCnq/tEOov0hAuRCp/W/.../5Y1PZQQtXtejBXsfZqeuC1xHI9IvN0CURiZlYU9f4Zfp25carpD2Cdb5U7eWQ3trDQzst8oR3Me0YxrSJ8wsVj0kAcvDoqHmWbCIY916ecfe aGqn5330Mwo53DS9Gf7hAF3Z9

Remove itunes-12-0-1-26-32-bits.exe - Powered by Reason Core Security