k-lite-mega-codec-pack-10-9-0-32-bits.exe

Web Installer

The application k-lite-mega-codec-pack-10-9-0-32-bits.exe, “Web Installer Setup ” has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from d.baixakifiles2.com and multiple other hosts.
Product:
Web Installer

Description:
Web Installer Setup

MD5:
81148d5dd4315b42679d5ddf53bfe8b1

SHA-1:
ad268b991a6ce1bdbcf080ef5d8b279b5a87a33e

SHA-256:
22579b6a13b81cc1d45af3035aa4074e0fb93ee62f7c42c0dd1613ae35496dc4

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/26/2024 1:20:40 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.200.132

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.1523

Comodo Security
Application.Win32.InstallCore.DAI
20682

ESET NOD32
Win32/InstallCore.QL (variant)
9.10997

Fortinet FortiGate
Riskware/InstallCore
2/3/2015

K7 AntiVirus
Trojan
13.190.14604

McAfee
Artemis!81148D5DD431
5600.6865

Sophos
Generic PUA KN
4.98

Trend Micro House Call
Suspicious_GEN.F47V1231
7.2.34

File size:
672.5 KB (688,617 bytes)

Product version:
1.6

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\k-lite-mega-codec-pack-10-9-0-32-bits.exe

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:0MEFaWVBs7un8g7iGYYz/BgsC7HtJUzRfZR4QtFxT6nF8lrY2Hj38J1V:0BF70in8I/z/B/CztJUzRAQj0nFirRMt

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file k-lite-mega-codec-pack-10-9-0-32-bits.exe has been seen being distributed by the following 9 URLs.

http://d.baixakifiles2.com/?ic_user_id=9289&data=An4r2g9mWrmmF62cBB8sXRg6XRLkeypXIJug4kyD5lMRScgiN5OsuNtTmYmZAUyBH1sRnywj2 sG TD6Fox48lmbjbiTrxz0SPCpmsnU E4dsGxhuNJ4UB2z275D7zhBEli9G7xu/HyLHvE3OszxlgJ1jEWxXI2XWHFb950aqDTDCZ2ucgymy/TwQle8Bn4a0uSu/iSED5/uEfECUXPFKocYiYl63cjdFOHkBrRv5t/V0ovIxexl8iPDAKniiLDL qPgaIG0cNYEgebRncR2LMpGq9wIETS6wWrEppQ2NuaMuYNO3CIFS2xzBQauUt1iIR27s/4bSHZgu/dk0THhyqjWFJ8R3Ww3atktfGgNz4m7pVIDKXRo14M8BRjhgZYKx2SKctaqn7QRKXDXyg2hCJnBIFBIA8W8DhB1lzrveQVFHXjCE4i 09MiK vf1BL0EWsbEdGwz19 4tSVv/jIglRCSnQz3mkpCTGdQ7LKzEN23wnysxuUl81d1mdXc/lx5DiQ3xVQ NROC97t8E1PMNUnNvFtIqGtJ4h70itbxcWz2bOjcThKreIrkEvDj2w3CUWzdL/r 8AFrwfKdUJ5jP09LzzxBRqJCneIruAGeN93qSpVP0Nmrv0LsAgVrQczCwt6rtvLVY/kS3TIYDs7IEyH7zfS5yPpg0Swz5k1hvTXBKEafYuiic9PpjBaHg7ElchAar6ogYvkmWXO8uDMUSPwg8kxCaClH5EIPbUFwAb2m7P6lsf9gZJLkQ==&key=T40faOXhz6Uazb4gFlAONgukMVgDQCUmgddSMie8 Ozz0fTO//MeCyrU5E4blOMkb5R3T9nEEP6PZDvipoP79ijvoXXGpZBdLxag4z27zG9WllGuMWGJ619jYOm7x56VXDPOfFRjDSs4sZAvEEtHrqyWsfjnUYfPa6Ie2j1 B0HPMY5YMqotZT

http://d.baixakifiles2.com/?ic_user_id=9289&data=GBtz 4PpaiYjw1I/IQPIKfdb055 p8W6jaFppnmEJxs5geXfcF6gxgsnzVdqEwwqFyYOwmZjwhzlgn0UiGSxKiFJhG5E0EOhNZf4/EQfyxhK6itp3VPOp4KxT2JJxlAtfCXwKCghHxK8cfDN xLcjIfGEaY2phD1Vurs 73yBxPFoEFKllT88VvyxO4H3BQ1TQU0KIwfLcRbjMdHUDZmbtUUnyz io0To8zzSuDmtV8eZOtleb3RHU/DYWeaBHjMxhhoDWJTofLgtIOgg1gEmPYZP8YqTCucKmOPLRKvMTwP6NTVwzBBuk68Hu5speQdiCPqhSFB1W6U56zRr8rncAFrnAxCRH2KuPyoQ2F8Wu8nZZDRsI3DAYtFcA96OCYJcD9QR19LnEVOnArRIe5XwCFW/njnSA4SUkPobnhFmU GewvmEsQqD0asYlI0UZmFBI0lgiIEYiyeuEcEH7pQBn2dUS/a4n8Ayulv/OxU2MKp2780ppw5wlXEIjKMOI3DW6WhTtksY6OYi79/KpxjAH5XUdVSoiFx6qr dDSEPU9g9gDCmljQmDkPOWsBnvLhEe73wj4MWceGyJTyusoeGUgpYE 2MVEHBsS7HCkx9NO4kUjnwl9CeZqlxM0UMIkLfLvjwhTh0t9j0LfSSXMPbW5DoLwQbNwWTFW7yp8zX7mS1S48EoBRieRUosaxZklLElUIO3GtFquwNKLX5yXFxB/FAM4Bq22nYJoT/hLj50ZiZe9Y OYFuiE9Ng==&key=qiBEDMa85YlMfegA8OlRfd11WUvvceXSzXDplog4gHW0remUphmCk/.../sXLLAmbjNJ0LDYSK

Remove k-lite-mega-codec-pack-10-9-0-32-bits.exe - Powered by Reason Core Security