photoscape-12505-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application photoscape-12505-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
f309abde6bc3d0bd03ea9f7509e3e4a1

SHA-1:
503968084282953388ed65c756484efa45ad01f6

SHA-256:
997f96ca488414a6433d60f2a9fe5ec0d4809a6d8e1ffed3cd0a6b9d02e024f7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 6:00:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.10.6

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\photoscape-12505-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:KCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:KrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file photoscape-12505-dp.exe has been seen being distributed by the following 50 URLs.

http://www.clearuniversecapital.com/WVl6OTRQV2RqSlRKQ05rY3hOMDVtT0ZVbE1rSnZOek5vY2t4Tk5GQmhhRWsxTVU1emFVSTNNamhvVTJSUlNXTnpka3gzSlRORUptTTlSa01sTWtKb1FtMUJkRXBGYlhjd2JXZGpNblV6VW1wclQweDFibFY1WjNKbFV6WjJOMnB0YVRkTWRHdFhlRWw0ZDBnMmFFdzBiMUozYjBFNFFXOTFSRkEzU0Raa1kwOHhVRkUyTlhCRE1uZG1KVEpDUXpsU2VtOUVaR2RJVEhWalJpVXlSbmgwYkdOTVQwSmhaMFZ4WmxoVlV6QkVNQ1V5UW1JeVFqRnFkMU1sTWtKcGFGSXlUbVV3VEdkeGNEVlZUbTFHTW01Q2F6ZDNkbU16TTJ3NWR5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWm5jbUZtYVd0aEpUSm1VMlYwZFhCZlVHaHZkRzlUWTJGd1pWTmxkSFZ3WDFZekxqY3VaWGhsSm1SdmQyNXNiMkZrUVhNOVVHaHZkRzl6WTJGd1pTMHhNalV3TlMxa2NDNWxlR1U9

http://www.todaymetabundle.com/WVl6OTRQV0pEYUhCTFMzWnNRa3BLUzNFMVMyRjNRVTA0U2tFM1RURnNOVE5VYVZOdmRFeDRiWHA1VTBoc1kwVWxNMFFtWXoxT05WZG1hMGhIYjBGNk1rTTVkVFZ6YVVOUGF6SlRNMXB3VGpGR01qUkVjVTB5WTBRbE1rSkpSMkoyT0RFME1FRnJNR3RaTjB3bE1rSmllVVl5WTFwTGFsZEtObFZpUVZwdlJXMXZXSGM1VEhaNFNrSnJVamRQUm5WTWFHVnFhMGR1YVNVeVJrWk9PRXBGVTJKaFlqRnFRVFprY1ZOd1dHd3lla2x6YTBSbWNsRlFkRGh5V1RkTlJucDJUMlFsTWtaaWFEWlZNMWM1UTBwSVdWSmlVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptVTJWMGRYQmZVR2h2ZEc5VFkyRndaVk5sZEhWd1gxWXpMamN1WlhobEptUnZkMjVzYjJGa1FYTTlVR2h2ZEc5elkyRndaUzB4TWpVd05TMWtjQzVsZUdVPQ==

http://www.headcycleuniverse.com/WVl6OTRQWEozU0hSNE5GWjRNamxvVTJ4UmEwc3pjamhuVlhsMVQwaEdRVFE1TkhoRVNEZFFaeVV5Um5sQlJGVlFVU1V6UkNaalBXUmhNVmxLTnpsQk5XdzRPVmRhVWt0a1l6aFZiVzVNTjBkMVRERTRaekpuV21KTGRrTlNNakUwUVdKT1VuaFJZa2x3ZFhsMGR6TTRORkZFWjFrMFFraHpiVUp5UkVsdFVISnJiRGxVVkdwR1NGa3dTVTFMZFZSUWRXVlZTV2RrTWt0S2MwZHJhMnB1UjBvM2QwUlFZMHRIVlVKNFRYcDZXSGhSTkV0YVNuTnVZVVZCZEZkMFIyOW9WakprTWtkRWJuVmFVRUpRVVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aemRHOXlZV2RsTG1SdlluSmxjSEp2WjNKaGJYa3VjR3dsTW1abmNtRm1hV3RoSlRKbVUyVjBkWEJmVUdodmRHOVRZMkZ3WlZObGRIVndYMVl6TGpjdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VUdodmRHOXpZMkZ3WlMweE1qVXdOUzFrY0M1bGVHVT0=

http://www.deliveryheartconecpt.com/WVl6OTRQVko1Wm1GdFRHOUVURGRpYm5GbFRVSXhZVGhuZVU5bWFHTmFialZyWkc1eVVqaHBWbFpSWlVsV05XY2xNMFFtWXoxeVRrdFBhRlp3YlhKcU5WbG5VRUl5TWxjMWN5VXlRbFozVFhGcWVITkdKVEpHT1hSaFRVWXdiblp0YUhKemFEQXlPR1JHUWxCa1JWSm5XRWhMV2tkMVVWVnRSbTFFTUhOWk0zWmFRbE5IY0dwMlVFcGhSWFpHSlRKR2RUaGpjM1JYVjJvbE1rSkhkemd6UjBSelp6WjBiek0yTkVFbE1rSnhWbk0zUzNrNGEzbGtZVTVyWmxKUVlqaFBaR2RZYWpkMGJYaFdOSG9sTWtaQ1RIRmtSR0pzU2tFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpsTmxkSFZ3WDFCb2IzUnZVMk5oY0dWVFpYUjFjRjlXTXk0M0xtVjRaU1prYjNkdWJHOWhaRUZ6UFZCb2IzUnZjMk5oY0dVdE1USTFNRFV0WkhBdVpYaGw=

http://www.grabappsdownloads.com/WVl6OTRQVFZRVUVwellrdG5hbWMzT1ZkRGRrWTRSVWhJZW5WYVNUSm9WQ1V5UWtaTmIwbHRZV2hGWjJwTlJYVlVjeVV6UkNaalBUTlRRVWQxZGs1NVZrbFVWaVV5UmxkMk0zUkNSU1V5UWtsVFkxUmFNR1V5TTFGUlZsa2xNa1l6Ym5GdGVGRkVSemhCZEVWQ1VUZGFhRkZQUWxFNVJrUkpTVzFZTWtsd1MzUndaM2hqWldaRFkwNWFOMmxMUVRKcWJGVlBTbEY1ZFhSRlZXZ3hjbVZWY2xrNFRERklTRXRrVDJ4dVFUaGpWekZwTkVVeWRtMGxNa0o1T1VoWmRXOTRhMWx4VlRkcWNWaGpZbnBVWVZKV1UyNVVSblJuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1aVFpYUjFjRjlRYUc5MGIxTmpZWEJsVTJWMGRYQmZWak11Tnk1bGVHVW1aRzkzYm14dllXUkJjejFRYUc5MGIzTmpZWEJsTFRFeU5UQTFMV1J3TG1WNFpRPT0=

http://www.clearuniversecapital.com/WVl6OTRQVTlUTWtWWU5GWmFNVzkwVFhoWFl6ZzBNa2N4ZFRsTFJWZE5VbFZwZHlVeVJuQTRNbGcyY2xscWVqSmpieVV6UkNaalBUaGFkRE5HTm1KM1oxRlRRalZzVVd3MlZuZG9WMmxUZW5wbk56WnNhVTFXY25wUVdYTjRSblZKWTNKTVkwRm9kRTlwT1V0cEpUSkdSemQzSlRKR2NVMVFZVmh3TURWV1IxQjNkR1ZoTjNKa1FWSm1lREp5Y21WMWNraGxkRmd6TTJKeVZsUkhUMlVsTWtacE4xRXlNR2czV2tOVk9WSjFjbHB6YnpGc1NGTjJTVFJDSlRKR05pVXlRbHBhVVhFd05VdFhUVmxtTjFsNWFTVXlSbTRsTWtaRVZuQkJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabWR5WVdacGEyRWxNbVpUWlhSMWNGOVFhRzkwYjFOallYQmxVMlYwZFhCZlZqTXVOeTVsZUdVbVpHOTNibXh2WVdSQmN6MVFhRzkwYjNOallYQmxMVEV5TlRBMUxXUndMbVY0WlE9PQ==

http://www.clearuniversecapital.com/WVl6OTRQVVIwY1ROa00zVnNXRWRRWnpBemRtSk1NbVZZY0ZWM2FYUXdUMnB4YTFWRVRtWjNNRGMzU2tkeFZITWxNMFFtWXowek4yWktNekU1UkRnbE1rWktURkJGWVdGVVRFTktaVVZLV1RoM1YyZzVjMUZZVDFCaFdFbHlSVlZ4Y0dWNlZXeHFkMnhpVGxOd2NrUkZZbVY0Wm5KTWIzbHlTWEpUWmpsaE0zVlhiemQwWXprMlJHbEdTMkpuZURoQmNXMXhkbmhwTlVsR2R6Vk1aWFJLT0dONmRqTktaMmxMUmpkYVkyZzFkbHBwWVZWTE5VUTJZMm8wTkNVeVJqWnhTR05XU2paTE1EVlVlRzFCYWpWM0pUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVpuTjBiM0poWjJVdVpHOWljbVZ3Y205bmNtRnRlUzV3YkNVeVptZHlZV1pwYTJFbE1tWlRaWFIxY0Y5UWFHOTBiMU5qWVhCbFUyVjBkWEJmVmpNdU55NWxlR1VtWkc5M2JteHZZV1JCY3oxUWFHOTBiM05qWVhCbExURXlOVEExTFdSd0xtVjRaUT09

http://www.tagtowerscapital.com/WVl6OTRQV3RFVERkWFFXZFlkWE5FUXpCVGNrRkZZVzE0YVRKMmVHMXBPRm8zVlhabGVUa2xNa1kwUkc1a2FHZDJheVV6UkNaalBXWXhVbFprU25welEyVXdkWGRKY3pKaE5uRTVVSFJKTUdkSFF6TXpja05pZVVadmRHOTVjWEJSUjBkT2RGRXpabXBITkVKNU9USXhUVlJTV1cxVWJYQk5NR2x0Y1ZNMk1GRldSMWR5VldGaGMyaGxkRkkxTVROTWQxcFhUVTlwWkZOM1NIa3plV0ozY0c1UGNWQlljMkZSUVdwU2FURmxlR2xKVVd4eU9YRTFURTF4VnpoRGFXbG5Uakl5Y1hKNGNYWnZSRVF6UVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aemRHOXlZV2RsTG1SdlluSmxjSEp2WjNKaGJYa3VjR3dsTW1abmNtRm1hV3RoSlRKbVUyVjBkWEJmVUdodmRHOVRZMkZ3WlZObGRIVndYMVl6TGpjdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VUdodmRHOXpZMkZ3WlMweE1qVXdOUzFrY0M1bGVHVT0=

http://www.contentdownloadmega.com/WVl6OTRQVkpsZVRBeFREaFFSSFJYVG5GUFptZHBXRTVHV1ZCWFJFeFRTVkI1Y1VKdE5uSXhSazV1VFcxM1kxRWxNMFFtWXoxaE1GSjZWM3BKYjAxSllYWTFXR05yY1c1clVtWTFaVkJMVEZWNWJ6TnZPVzVVY2xGcVlubHBUV2x0VUZZMVUxZHVTalUwU0ZsSlNrdEtZbWRzY25Oelp5VXlSbEVsTWtKT1MwNVJaVVpKVDBVbE1rWnFablowYTJWVWQweHFUMkpZSlRKQ2NrbDNPRVJQSlRKR2RYUlFPRlpHV0hSNU5IaE9aRkVsTWtKQ1JYRWxNa1p3U2pnemNscFJSRzlUVURCVlJqZEhXRmhUVG5KVFozQnFibEkxY0hsa2R5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWm5jbUZtYVd0aEpUSm1VMlYwZFhCZlVHaHZkRzlUWTJGd1pWTmxkSFZ3WDFZekxqY3VaWGhsSm1SdmQyNXNiMkZrUVhNOVVHaHZkRzl6WTJGd1pTMHhNalV3TlMxa2NDNWxlR1U9

http://www.todaymetabundle.com/WVl6OTRQV1JQZG1WcVNFRTNia0o2VVcxU1kwdFRhMmRvTW1oc2RFNDJSVEV4WTBSMlJIZDZTMEUxTVdKcFdsVWxNMFFtWXoxRlFVSk9iRlJQVG1adFpUUjJiazU2UmxOS01rRnhaVUpKY0VSdk1GbzJVR2g1SlRKR1pXUTJSRzlRYmlVeVJtODNPREZhUnlVeVJuZFJTRGR5Tm1WbU16bEZUREpoT1d4NlEwcGhjMjF2Um1KMlowRkljbXBCSlRKQ1pFOHpWM0U0UjJSWWIzRlphbTFvWTJobU5YWlBZMk5ZU1RCM2RYQkpSR1ZzVjFacVdHWXhXRmxhYUZOMlRuQmtla3QwZFNVeVFqVnJWVEZpZWpseE5FWndka1pSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1aVFpYUjFjRjlRYUc5MGIxTmpZWEJsVTJWMGRYQmZWak11Tnk1bGVHVW1aRzkzYm14dllXUkJjejFRYUc5MGIzTmpZWEJsTFRFeU5UQTFMV1J3TG1WNFpRPT0=

Latest 30 of 52 download URLs

Remove photoscape-12505-dp.exe - Powered by Reason Core Security