picasa-12733-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application picasa-12733-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
84852353df969f5770a26b42e0c5cc01

SHA-1:
421a38038d93695f1016defb726dc9e8f42e0c9a

SHA-256:
72857ba266116df4fb5c5c2df74ebeb06cade00721171bebc987f69b1e4afeb9

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/23/2024 7:49:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.23

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\picasa-12733-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:eCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:errwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file picasa-12733-dp.exe has been seen being distributed by the following 42 URLs.

http://www.vaultschuckleapplication.com/WVl6OTRQVFpvV25GYWRqRkdPVWxvWW1sSU4wODROR2RQWkVKcVozQjJWVGRDUm1SS09YVlNRMkZLV0VsUVlWVWxNMFFtWXoxbE9VWklVVXBxZURkcWRUQjJKVEpDVFRobFpuWllhekZwY0hwT2VXNVdlR0pwUkhONFExUk1OMVpXU2pWTlozaElPVmRzVUZRbE1rWndOemN3YjBKcGNTVXlSaloxSlRKQ1VtbGFkalZsVFhoRVQxWTNjVXhZYTIwd1NFaHZaWG8yYW1oM1ltZDRiMFJSWjFGVFIwSWxNa0p4TjFGelJqVTFkRFExU1RGNGVHUkRjalJhVjBOcloyRklTbTlJTjFjNVUwOWxVa0p0VWpkNWJHTlhKVEpDZFVFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpuQnBZMkZ6WVRNNUxYTmxkSFZ3TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJwWTJGellTMHhNamN6TXkxa2NDNWxlR1U9

http://www.tagtowerscapital.com/WVl6OTRQVEpVU0ZKVlptTjRSbUpwU3lVeVJsUnNVa1ZOVnpKWWFHTjVNV1pOU1d4SVNFZFVVRkpTWW5weGFVNHlZeVV6UkNaalBVSk1Na055WXlVeVFsVlFWbVFsTWtKVWNVZzNTSGgyZDI5eGJYQXdObXAyY0cxcFVUUnVWVzF6VG5SR1J6TlFWR05ZZUhoWVJXVjVZbmgwWVhoeWRURnZVWFk0Y1RSV09HdGpkVXhSV0ZOalZuUnBkbTFrZHpSVFlXcE5RMWxTUmtWc01FczJkbmhsZFRWdmFFaHBXa3RXTTFoWlZrMXVaa1JVZUNVeVJtVkNKVEpHUjFBbE1rSkdWbk5IUmpZek5qQmpZbWN3Y1VkaFZFSlFWM05XYUVFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpuQnBZMkZ6WVRNNUxYTmxkSFZ3TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJwWTJGellTMHhNamN6TXkxa2NDNWxlR1U9

http://www.bundleflashapps.com/WVl6OTRQVE16YzNWSGVFZG9aRGhqTVU5TVp6VkNTelVsTWtZeWFFcFFVazFzWTNCT2FVcDRlWGhDYkdjemNFeFZPQ1V6UkNaalBXWk9ZbUpYVUU1QmVVOHlRbFY0UjJseWJGVTBVSGR0SlRKR01uRklKVEpHVTFaS1ZUTkJZMlZ3TTFsR05rZHFXVFJUSlRKR1VFSkxia1JXU1VOWE5EUjFkVTlQWTNWRWVWQWxNa1pETm1KTmJXZDNaa3RYVFNVeVJrNW9kRGRRU25WTVdXbHNWREl5UkVkVWVWbGlRMHhoVURCSVJGWkZheVV5UmlVeVJuSmhhM0ZwWlU5TFZFWnFabVZWYzJRbE1rWmxNRk5MTjBaWk0zZG1PWE5KYm1WQk5UQmhibmNsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYzNSdmNtRm5aUzVrYjJKeVpYQnliMmR5WVcxNUxuQnNKVEptWjNKaFptbHJZU1V5Wm5CcFkyRnpZVE01TFhObGRIVndMbVY0WlNaa2IzZHViRzloWkVGelBWQnBZMkZ6WVMweE1qY3pNeTFrY0M1bGVHVT0=

http://www.headcycleuniverse.com/WVl6OTRQV3BOYjIxRFNEaGpRVUZHYTA1WGNYRkROM2w0WVRONWVIQTVSMHBRSlRKQ09FTTFjMGhhWkhJbE1rSjBjR2RuSlRORUptTTlZV0o2TXpRbE1rWkNKVEpDU1dWTlRtWkRlRTUxUWxwa2NtNW1lRFIxZFUxa2NIRlRWMGhZZW1oa1V6RkhZMFZDVlZONlowTklRM1k1Y25aR1ZtTkNOMVZRV2s5bVVrWTVkMXBZVFRKM05XeHFWaVV5UmtsUFMxTTJOMkpOYWtaSE9FaEdiRXhpWjJrelFWcHJkamRpUmxrNFlUTnBKVEpHT0VJMVV6WktSR0pWZDBOUVJtdHlSWEZMUzFOQk15VXlRamxzYmlVeVFtbFNkWGxIUnlVeVFtWkxOa0VsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROaEpUSm1KVEptYzNSdmNtRm5aUzVrYjJKeVpYQnliMmR5WVcxNUxuQnNKVEptWjNKaFptbHJZU1V5Wm5CcFkyRnpZVE01TFhObGRIVndMbVY0WlNaa2IzZHViRzloWkVGelBWQnBZMkZ6WVMweE1qY3pNeTFrY0M1bGVHVT0=

http://www.bundleflashapps.com/WVl6OTRQV1o2YUdOSFVWVnBNVzVzVTJwVlRFVllUVXhVUm0wbE1rWnVSR1ZZUVVKWFdsRmpVa041UlU5TWFqVk1TU1V6UkNaalBVOVhaV1ZzZEdOSmExQm1UMDFLT0c1MVNVUnZVMFpSTVRkSmFtODBUWGxDYTNoR2NYSm5PSFJLU0hwblYxVllhRTl2TlNVeVJrVTNZM0JYWldvek4zWnBkVmg1ZERad1NHcHpTRW81UkNVeVJuUWxNa0l6Vm5KSVozaGFKVEpHVUdOTE5uWndkWGRtZUVKcGVHazRRVzlvUmlVeVJpVXlRbk5qVDFCalpsbHpWMVZXU2xrME4wSnBRa1ZZUkZWVE9EQk5hM2czVm1oYVFYWmxVRlpqVERCbVp5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWm5jbUZtYVd0aEpUSm1jR2xqWVhOaE16a3RjMlYwZFhBdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VUdsallYTmhMVEV5TnpNekxXUndMbVY0WlE9PQ==

http://www.clearuniversecapital.com/WVl6OTRQV0pDUVhRek56QkZNakJhT0VZeGJ6TllVVEUxYm1sWFVXWlFWVlJoV25vNWRHTXlUbEYzYWpCdWRXY2xNMFFtWXoxaFkxUWxNa1o2VTFKVlRXdHpXa1JwUjJaV1ZXbE1iQ1V5UWtjMGRYZDRWRGxtYjBWWlUxUkdSelp3WkdKU1F6bDBaRE5YVUVrd1dsaDVNemRDWWpWMVUzWTNkR2xKZWsxelozSm9UelZFVEZsWE5rRTBURTlQUW1WSGRWVmtNbmt5YzBZeWIxZDJSMmxTTkZVNFFrcGlaMnhyVVRSWmVpVXlRa3BOV2t0MFNVZHVWV1JpV1dKR01WUjBTSGhpWVRjeVdYcHNNbkpLZUVKRlIzY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1aM0poWm1scllTVXlabkJwWTJGellUTTVMWE5sZEhWd0xtVjRaU1prYjNkdWJHOWhaRUZ6UFZCcFkyRnpZUzB4TWpjek15MWtjQzVsZUdVPQ==

http://www.headcycleuniverse.com/WVl6OTRQWEZoWjB0R1JVd3pURzl3V210b2RrZHNialZaVms1SVVEbG1NRmRXTVVOTk9HZHlhWFZ0VmpseVExVWxNMFFtWXoxaVVUbExNbTFYZWtKaGREazJkVmRTWld4dVptdG5Ta05FUW5SUlRXdHhSVFpsYlhrM1lWQWxNa1kzWTJkUlpqZzVUalF3UTJKVlZUSmtUeVV5UWpCRFJIQkJOSFZFZDNKck1YaDFkbnBsUWtaWlJVTTNZbHBFTW5wdVJUVjBjVXhuWjBjMloyNW5kbGxvVkRCcE9HdGlVelpRU21OQ2NIWnhZekJCZUZVNFREQlBTMGxpVUdSMFIwNWphWFZtZVZkWFdIcE9Uek1sTWtaM04wRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1aM0poWm1scllTVXlabkJwWTJGellUTTVMWE5sZEhWd0xtVjRaU1prYjNkdWJHOWhaRUZ6UFZCcFkyRnpZUzB4TWpjek15MWtjQzVsZUdVPQ==

http://www.headcycleuniverse.com/WVl6OTRQVEpTYUVWdlMzZ2xNa1pEV0daaVYyeFJaMkZUVUVkMlZsQjNVV2cxZDNZbE1rWkhXRmRXT0c1V01VVldjVTlWSlRORUptTTlKVEpHV0cwMmNXdHBOVTV0YzBKQlYzQkNjMmxJTlVvNFIxVnhNMFZ1WTJWRFEwVXhOM1ptWlRWcFRtRTNhMDlGYm1ReE5tVjFOV2xDTW5WbFEzSkRjazlLVjJsb1VXeE1OVTVoWmt4VGFtdElTR05aY2poVlRFTXdTR0ZSUzA1WU1GTktZV3B2YjJwclNTVXlRbUZzUWtSSFptUklkbTQzUVZrME9WUlhWR2x3UVUxeWJFaERlVmhFU2xJMlQxRnlWVk4yUTB4SFEwMXVRU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

http://www.clearuniversecapital.com/WVl6OTRQV0lsTWtaelR6Z3hkSFpsV25sSFVsTjRWRkZ6Y2tOcWVXcHJWa0ZTY0VWRU5VeHJPRGxZYkhWR2FIbGFheVV6UkNaalBVSktiR2RTVEhsU1pUZzRiR1J5ZEhWcFUwbG5iU1V5UmpsUmFFaHlVSEJLWlVScE1YQnBTV3R4YmpOa2NHOVBRblZIZDJWS1pVbHphakJGZUhRMFN6QlZaMUZtTVZsRFFsRlpaR3hzZVVJeU9YTkRXSGREY3pGeWNFZzJUVVpsWkV4UU1FRnJWWHBMY1cxTU5rNUJNSEpQVWt3MVQwMW5SVk5GSlRKQ1pWSWxNa0p6VG5aSFUyTjBjRE5EU1U5YU1rSTFiSFJ4V0VRMFVESnNVU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

Latest 30 of 42 download URLs

Remove picasa-12733-dp.exe - Powered by Reason Core Security