klite-codec-pack-13137-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application klite-codec-pack-13137-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
d8d77491963d1059e2603d1ab137c1b3

SHA-1:
c24757a4b3ffd15caa13cce0cfe52898eb50a4b8

SHA-256:
5a0ed7d193b062124bc23f57635871058c6164944f10d4fb0c4460f0a42115bc

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 7:21:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.18

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\klite-codec-pack-13137-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:hrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file klite-codec-pack-13137-dp.exe has been seen being distributed by the following 42 URLs.

http://www.tagtowerscapital.com/WVl6OTRQWE1sTWtKbWNGcDVWMkpwU1NVeVFqVjVjR2c1SlRKQ2VGQmxjMUIwUm1WTVJtOUJWa2swV2twTFowWnFOVWxSZGxrbE0wUW1ZejFFV0VWelNXUlBNMlZxYW1oWlRqVWxNa1pXUmt4U1NWRjJVVTlZTUVOTlIxZEhRemxKWkU5U1N6Qk1lRUZVUWxoRFJFWkxUVXQwUlZKTVlqaE9NVWwwUTJkdWNIZDFjamhSVjJGcUpUSkdURmhpSlRKR2MyNWFlbEJOVEdsWFZVeE9SV1ppVEhsNVFqUm5XRXhsUzB0MFRuSllOVFZFZG1kRVRYSlpiRlp3VTNkTU1UaGpUbUZ5YVhWb1RISjBXRWxHT0ZaUU9VNHhSRVp5YVZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpIQnpkRzl5WVdkbExuQnNKVEptYlhWc2RHbHRaV1JwWVNVeVprc3RUR2wwWlY5RGIyUmxZMTlRWVdOclh6RXlNVFZmUm5Wc2JDNWxlR1VtWkc5M2JteHZZV1JCY3oxTFRHbDBaUzFEYjJSbFl5MVFZV05yTFRFek1UTTNMV1J3TG1WNFpRPT0=

http://www.todaymetabundle.com/WVl6OTRQV2RyZUVkdmN6ZEZUMHRGZFV0Sll6aFlhVlZ0ZEcwbE1rSlFVa3h3Y0RWTFpGRXlja0p3T1dsWGJHSWxNa0pGSlRORUptTTlKVEpDYWtzd1NHVk9VMWhoU0ZoSmF6Z3llVGw2YWpGa1dHWmlTMWw1TkdJeGNqUnBkVE5sYjJKMFltUkdTR1ZtVVZGVWNVcGlWR3haYUVzM0pUSkNXbWRQU21kT1lXNGxNa1pGWVdsdGNFbEZlVU5CTkVWS1FXOUZPQ1V5UWxwSFRtTkZVVlZDVTFSc2FIZHBibnBXYkhOa2RGcDNSbGM0ZDNST1pFRkROSEZPWkd4a1JHeEVWU1V5UWlVeVFqbGlUMGRxVTBwVVEyWlhVMDltVTBKTVMweFJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVJ3YzNSdmNtRm5aUzV3YkNVeVptMTFiSFJwYldWa2FXRWxNbVpMTFV4cGRHVmZRMjlrWldOZlVHRmphMTh4TWpFMVgwWjFiR3d1WlhobEptUnZkMjVzYjJGa1FYTTlTMHhwZEdVdFEyOWtaV010VUdGamF5MHhNekV6Tnkxa2NDNWxlR1U9

http://www.stockbundlecentral.com/WVl6OTRQVlJ3ZEhCWVNEZ3lVREZrZURoNk5rOXZOVVIyWmlVeVJuTlVaRkpCYW5KRVZrMUNRVVZDVjFCdlVVOGxNa1pCSlRORUptTTlTMFYyZEZGblpVRmpZMjlNWVRCQ2RqZEZWRk5WYmpoaVZGRnZRV00zZFhoaWFWRkhUVXhVVTI4MVptSk1aMDFYSlRKR2IxcFNUU1V5Um5ZM2NsTm5Oak5sZEZKT1ZuWTBjRk4yYlZSTVMyazVkVEpsV1RWNGFFY2xNa0pCYzI5V1pWSkdUM2d6SlRKQ2RVTTFXbWN3WVVVME5tWkVVMUl5WjBNMk1HbGpSR0V3ZVVKVU1uVktlVlpOZFZKUmFISjZaM1ZwU2pBNWNtaEtTMlZPVjFFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpIQnpkRzl5WVdkbExuQnNKVEptYlhWc2RHbHRaV1JwWVNVeVprc3RUR2wwWlY5RGIyUmxZMTlRWVdOclh6RXlNVFZmUm5Wc2JDNWxlR1VtWkc5M2JteHZZV1JCY3oxTFRHbDBaUzFEYjJSbFl5MVFZV05yTFRFek1UTTNMV1J3TG1WNFpRPT0=

http://www.vaultschuckleapplication.com/WVl6OTRQVFExT0VwUk1IUk9iekJsUkV0RVdrcHhRMmhwUjA5UE1UTlNSa1ZwZW5kUmVHRk5TelpGVkRsak5tc2xNMFFtWXoxUFFWTm9hVkZrWmxGbFMzVlpZU1V5UWxvbE1rSkhOM0FsTWtKS09IcG9kakZ3Tm5weVVVWTVWa2RpYzBjNVZraHVkbkU0WWpWT01YbFBZbXhyV2xCVGRHTnVKVEpDWmtab2MyNTVWbWxrTUdwNlJsTWxNa0pxY0ZSSU1YRlFTVEpPUlRoTGNXWmFXblowTkhSeU9YWnlZMHRRV25GVU9WTmxNaVV5Um5jbE1rWndaVFpWUXlVeVFrSnhhR1ppVjFOblNsSnBUbXhrVFhkNEpUSkdOM0VsTWtKUVoyaDNVR3BCWnlVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aa2NITjBiM0poWjJVdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVN5MU1hWFJsWDBOdlpHVmpYMUJoWTJ0Zk1USXhOVjlHZFd4c0xtVjRaU1prYjNkdWJHOWhaRUZ6UFV0TWFYUmxMVU52WkdWakxWQmhZMnN0TVRNeE16Y3RaSEF1WlhobA==

http://www.clearuniversecapital.com/WVl6OTRQVmRZYTA1VVltaGpPSGhGZFZWWVpra3llVE5WUTJOa0pUSkdVemhwVVUxS2QwdHRPVnBLUms0bE1rWWxNa1pSZDNNbE0wUW1ZejFhVDI1aU1uTjNRa1EyWkhKSFFXWmpaRlJrUkV4b1YwRlRiVGRzWXlVeVFuQjJZVVEyUldOdFdXNW5SbGxZWkRNd1VHVjFOekJ1T1ZRNFVFTTFiR3BQYmpaU2MycEtKVEpDUTJ4eVZFeG5XV2RxWTFoMlNEWjVSV2huVGpSTkpUSkdKVEpHYjNKU2NVWnpZWE5oYjBSWlExbEZTbkVsTWtaaVREWTRaVTlsV21VNU5YVjZkRTVyUlVST1RpVXlRbWQxYzNCaGVXUWxNa1prY0VnNVRuRkRSRlpSWnlVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aa2NITjBiM0poWjJVdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVN5MU1hWFJsWDBOdlpHVmpYMUJoWTJ0Zk1USXhOVjlHZFd4c0xtVjRaU1prYjNkdWJHOWhaRUZ6UFV0TWFYUmxMVU52WkdWakxWQmhZMnN0TVRNeE16Y3RaSEF1WlhobA==

http://www.headcycleuniverse.com/WVl6OTRQVmRxWTBoMVRsazFZVmhwYm1WNmFVWkVaM0ZPV0U1MGNXZEpTRlZPYVVaTFIxVWxNa0pYVFRJNGJXWjBZeVV6UkNaalBVMUNORzlYVTNwM1UwUm1KVEpDVXpGSmJVVktaMjAyV1RkM1dETmFKVEpDV1hRMk5EZzRlR2xQYWtkQ1pUQjFlbTkzV1VSbE16QTNUVEpFVWpoMmQxRTVlRFUwTW1sV1owUTFUMjE1VjB4dlNHWmxKVEpHTWtKU05IRkxkM3BCVm1wdWVEaHJkRUpZTWtGQlVXeGhRMmt5VEdsUWNISkdTbFVsTWtaWGEzaHFTa2xJVWpOdVZGRkpWM0ZsWlhsSlZEZHdVVlJuVURaT09YZHVkelZuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1Sd2MzUnZjbUZuWlM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aTExVeHBkR1ZmUTI5a1pXTmZVR0ZqYTE4eE1qRTFYMFoxYkd3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05UzB4cGRHVXRRMjlrWldNdFVHRmpheTB4TXpFek55MWtjQzVsZUdVPQ==

http://www.tagtowerscapital.com/WVl6OTRQWEZETUZWTWVUUkhRbE5IZEU1aFZIWnVRMFF4VXpRMFpuaG9TM1pxV2tvMU1tWk1kVE5sWjNJMVpGVWxNMFFtWXoxeFZ6aFBTR3AyYmlVeVFteEtUWGwyUWxSQkpUSkdjVTF6WjJNNFEyTlRWRWxxYlRGNE1VMGxNa1pDTUhCUGJrdHpabUpuTUZOdlJVVkJiSFUwVHlVeVJrMUllVE5OYmxaaFpGaHJZMGs0VTNwUVdqYzVabGRtT1drMmRYZENSVVkwUmtaUlRubFpUMFl4ZVdOUVJubDNaWGxrUTFsYU5pVXlRbGQ1WjNkak4zUlBSbFpXWjJSbVExRjFkWGx1WmxCVWFWRm5RekZITTJwU1J6bE1UV2hSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1Sd2MzUnZjbUZuWlM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aTExVeHBkR1ZmUTI5a1pXTmZVR0ZqYTE4eE1qRTFYMFoxYkd3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05UzB4cGRHVXRRMjlrWldNdFVHRmpheTB4TXpFek55MWtjQzVsZUdVPQ==

Latest 30 of 42 download URLs

Remove klite-codec-pack-13137-dp.exe - Powered by Reason Core Security