picasa-12733-dp.exe

Bab

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application picasa-12733-dp.exe, “Bab Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Bab

Description:
Bab Setup

Version:
1.6.2.1

MD5:
104441b92a642a2bf3a427ccc7e990d2

SHA-1:
b74c77ba438388a11162b17756753512968a04ef

SHA-256:
9784e5e9019a79554db018598748cf80860f28fc0e84bbba6d0d74edbccdcd8e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 3:15:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.4.17

File size:
951.2 KB (974,072 bytes)

Product version:
1.5.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\picasa-12733-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ovp7y5I5PpEla6JVWwIar2hfWz21GkqfQT7L7/bpoQOGZ/u:0x8culbVzIaKhc2gkqfQTz99Z/u

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file picasa-12733-dp.exe has been seen being distributed by the following 50 URLs.

http://www.dlchuckledl.com/WVl6OTRQV1YwSlRKR1FVUTNZa000UTJGbVJuVjJNWGx5VUVwTkpUSkdOa1JhYTNwbWVIZHRaREU1WVU1RGVFNURUV1JCSlRORUptTTljR1ZFUlZkcFFXTjVSalpoWWpOYWREQnVibTlRUWsweFdsQkNVbWxVY0RCSmJXaHRSbTlwZGxScVZqQnJiV1JUUkVWbmJEZEZPR2hFWkRkS1pHNGxNa0owUlVaT1JGRnphVTFPYjJWbFJpVXlSa2hvZWxoUlVTVXlSa1paTUZoWU9VRlRjalkySlRKQ2RYUnVVMWxtVnpJNFoxTmFUV2g1VURONWRWWnZaSFJhYmt4Q1JtNDNPRk5ETUdkRGJsQlBZazFUUlNVeVJuUTRURWh0WldrbE1rSjNKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabWR5WVdacGEyRWxNbVp3YVdOaGMyRXpPUzF6WlhSMWNDNWxlR1VtWkc5M2JteHZZV1JCY3oxUWFXTmhjMkV0TVRJM016TXRaSEF1WlhobA==

http://www.dlchuckledl.com/WVl6OTRQVlZoV1hoS1EwWTJRV2xsU25oSllWcE1XRTluYVZKUlJUUmpjRXAyZEZkR016TlZTRE5zYmxkSWJrVWxNMFFtWXoxM2RVSnNaVXdsTWtaT2EycFdiMHAwWjBKUmJWcHBPVzl5YmtsUGJuZFlKVEpDUm05Mk1VODFiVzlJWVZoNVRXUjZTV1JKUW5Cdk1sWTNjRkJuT0hSdGQyUjNXbFEwTkZoRmFHMXlORzlEYmxaSVRXaFpaRU01WmxRMVVVd3dhM0l4Vm1nemNtUndNVGRaVWpGbFlubzBTMVpTT1hnMFZYVjZRemxWVTBnNVRHTnVVVVJSYm5oemJWYzFVRXh5WlVNM1FUaE5VV3d5UlcxbkpUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVpuTjBiM0poWjJVdVpHOWljbVZ3Y205bmNtRnRlUzV3YkNVeVptZHlZV1pwYTJFbE1tWndhV05oYzJFek9TMXpaWFIxY0M1bGVHVW1aRzkzYm14dllXUkJjejFRYVdOaGMyRXRNVEkzTXpNdFpIQXVaWGhs

http://www.sendtodaychuckle.com/WVl6OTRQVEZoTjNsd0pUSkNORXR1ZW5aclRYVWxNa1kyUlRKVGRUbE5PVVZZTVc0MlNFTlNiVEkyWkdsQ1ZVVTFkazlWSlRORUptTTlhVkpYWmxCUk4xb2xNa1k0WldOd2RrTk1NblkxVDJZelRrdEtZVk4xV1VkQ0pUSkNRbVpZUlZKUU1VdDJWRTFQVEhrM2IyeHJZVVUwTVdwTU1GVWxNa1paSlRKR1NYTldTblZqVFZweVlrbFdhbXRTTkdKdVZuQk9lVEIwV25Gd1ptdHBTbFJ3VlUxQlUza3lKVEpDY2xKaWNGSkNhVFZ6Y2twWk1VUTBhMXBtTjJadVFteDJNbEV5TVRGd1lUQnZOemM1UTBSdUpUSkdkbUpJT0VwRmNIbEJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabWR5WVdacGEyRWxNbVp3YVdOaGMyRXpPUzF6WlhSMWNDNWxlR1VtWkc5M2JteHZZV1JCY3oxUWFXTmhjMkV0TVRJM016TXRaSEF1WlhobA==

http://www.quicknewbinaries.com/WVl6OTRQVXRtZG5aTGJWWlhhSGxQTldob1ZIa3phSFpYUmpsMFlUQlFTMWR1VmpBMWQwaDBVV2gyWkRKb1VYTWxNMFFtWXoxNVYzTjFhblpXUTNoaGQwdFJkbFpFUldJd2NEUkZWV1ZIWm5wSVlVNVpXRlpHUTI1aVZXOUNjRXhwYTBjeE4zWnFaRmQ2VmpaSldFUmhhSEl3TTNZek0yWmpWM2xSTlZCbU1ucEhlWEF5UTBNNU5HcHZORWtsTWtZNFZuTnNaMVZGZVhGNGFrcG1SVlZCY1ZkNWVXMDNUU1V5UmlVeVJqRnJUaVV5UmtjeWNVaFNjRTAwVGpsWmJIRm1lbkZYVGtkNlNFdFllbVJFZWtobk5FNUJRU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

http://www.chucklebestapp.com/WVl6OTRQWG96UjJ4Wk9XdzBWM0JTWkV4Q1MwMTNVaVV5UWpWb01tcHBhWGgwYzFCd1ZHTk5OM0JoYzFsT05UZ2xNa1kwSlRORUptTTlkMlpFWVZWM2JtRjJOMnhpT0ZaRFR6WkljMHBXYm1KVlRub3pPRkpFZWpKT2VGbGFhRTh5ZWtFNFZ6bHlSSHBZVUVrNGFGazVZMEZ0U0RSNEpUSkNUMGw1UkVjNGVUbG1RbFZDY0ZOalJGWkxVMjlYVDNaRFZGZ2xNa0pHUWt4NFlXcHZiMGN3U0Zkb05sbHRiR1puTm0wd1lsZHlTMGxSZUZseVNEZHNPRWRrY25JeVprNDBOWFZ6YlZKMVVVcGtSaloxY1ZwNE56WXpaeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

http://www.bundlebesthost.com/WVl6OTRQVGdsTWtKamJraFFkVzlZUlV4UFlXMVRNRGg0YWpFM2VpVXlRbTFZU0dGRGNtVTJSM3A2UlV0dGJ6TndUM2hSSlRORUptTTlhREZGZVhoNFkycDVOa3M0Ukc0NWFqRlBRM0p3TlZCQ1VVWTNObWhvTkVoTlRXZHFPVE5EZVZaV1ZIbDVTMDVUZGprbE1rSk1aaVV5UW1OT1ozY2xNa1prSlRKQ2JFZE1URVpSZUZBM1VrRjVhMk5IUzFaUWNWVWxNa0kyVjBRMFZHMXBUMkZpWVZWaWNUTTNSblZNVGpWYVJrRkRlR1JUZGpVbE1rSkNhbHBPUld4WVExazJaamMzVUd4SU5XdEJiblZGTjFSRFFtNUNjVXRRVFVwR09IaG5KVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabWR5WVdacGEyRWxNbVp3YVdOaGMyRXpPUzF6WlhSMWNDNWxlR1VtWkc5M2JteHZZV1JCY3oxUWFXTmhjMkV0TVRJM016TXRaSEF1WlhobA==

http://www.chucklebestapp.com/WVl6OTRQV0ZEZWpCeWMyOXFRM2hOWkd0d1JVMDNTemx5WW1KTldHTnJNRXBZTkZaYVluY2xNa0pMZURKTWFVMVNSU1V6UkNaalBYbzFZbFZxZGxsSGNXWTVWREZHYkRCbGFESTVVRE5pV1RsM1lsQjZVakoxZUU1b2RtdHlUbTFaZWlVeVJtRktSRmxDSlRKR2J5VXlSblZrYlRCV1FXZFRVbk5DT0Vnd2FYUndTVWRGVlRrbE1rWjVNamw2UzJkT09IaDVNVmx0VDFwcVJqbGhUbWs1YWpsSlNVaDZjMmRZVnpSTGVWUm9hRlJNZUV4bVUwVkxZMkZpYkhSM1RWZEJaMlZUVVNVeVFuQTVRbGhqUmpFeFYwZHBPSFJIWW5jbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpuQnBZMkZ6WVRNNUxYTmxkSFZ3TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJwWTJGellTMHhNamN6TXkxa2NDNWxlR1U9

http://www.vaultsgrabstock.com/WVl6OTRQVTVqTkZsVVFrMVVVaVV5UW1Ock1WaFFRbE13VGxZd2IzRndTRlphYVdaTVNIRkliVFZ5TUZWNFRtdExZeVV6UkNaalBXOXpiMWR5SlRKR0pUSkNUV0oyVlZOeVRGSm1jR3N4V0ZoakpUSkNRbVVsTWtadE1XOUVSMGdsTWtKeVFrd2xNa1pZWVU0ellWWjBaMDEzUmxoQ1oyVjBURmcxUjBNeWEySjJZa2huYkNVeVFrTnBOSFF3TjNWcWFrRmxVV2wzWW5SRE9VdG1UMU4xV0Zwd1YyaGpiR05QVnlVeVFqVlJUSEI2U3pOYWJtOW9WMkYzTVhScE0yZ3lOV0Z0UVVZbE1rSXlVbnBZWm5OU2N6SkhkbWRUVFVVeU5VbFBRMkVsTWtaM0pUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpZU1V5WmlVeVpuTjBiM0poWjJVdVpHOWljbVZ3Y205bmNtRnRlUzV3YkNVeVptZHlZV1pwYTJFbE1tWndhV05oYzJFek9TMXpaWFIxY0M1bGVHVW1aRzkzYm14dllXUkJjejFRYVdOaGMyRXRNVEkzTXpNdFpIQXVaWGhs

http://www.nowapplicationsranch.com/WVl6OTRQWGRESlRKQ2VYbEhXbmwyY2pGTFpWQjRTbWx1Vm01alRISm9jbGx1WVdNMVdVUktUWFE0TVVOaWRIaGtkeVV6UkNaalBYZHNUSGRLWkhGMWVVNVhaVFJYWlZWRmRsSlpSR05CZFVjbE1rWkVWMU13WW1kRlNuVkJlamhYZUhjNFRITnlSM05CYVVKUloyWkNaMmh5YjJkQ1dqRjJaVXR0ZFdKMVpYbE9jV1UyVlcweVppVXlSakJSYXpneU1uSktkazl1YjBjbE1rWXdla05RVFZVMlJXSjVZVmxVZFVKNWEyRnFXa3M0UkVadFJtdFphSGhIUzNsWmVtbGxKVEpHVWxsSGFETkZXbmM0TkhOWlYzZG1lWFZCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1ad2FXTmhjMkV6T1MxelpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MVFhV05oYzJFdE1USTNNek10WkhBdVpYaGw=

http://www.dlchuckledl.com/WVl6OTRQVkV5UnpoRmRHdHlOakI2VlVoR1RrNUVjbFIxYW1kRmRXNVNTM05PUVVOTmRHbEhkVlZ5ZDNCYWNqQWxNMFFtWXowbE1rSmpNbnBxUkVFNVlVSnVhbU5NY1dobFNrOVRVVlpJZVhaTk0wVjBjRUpaVm5kcVkwTktURXhEU0VaaFRVeFhlQ1V5UWtJeFFtZEZVRXBGVkVoWFJrMVZRVTh6V1VGeU56YzFVR3RhTTBkS2JEQkZiMUZDUTJJbE1rSk5XWEZHWld4VFJUVndXbGR2Y1dOb1pTVXlRbkpQWVhaNVlqa2xNa1l5UkZwc1JIcFVZbVkyTUZvMmFtVk5UM0ozWkZkNUpUSkdPU1V5UmtkM1YwMVhRemh6WlRObmR5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWm5jbUZtYVd0aEpUSm1jR2xqWVhOaE16a3RjMlYwZFhBdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VUdsallYTmhMVEV5TnpNekxXUndMbVY0WlE9PQ==

http://www.chucklebestapp.com/WVl6OTRQVUp5TldnMVYwOUVNMk5aVm0xblNuQk9NV0pITlRWSVNsWmlTMHB3YW5aQ1UwSlJTbU5aVUVKd2Jsa2xNMFFtWXoxbldrRmxaMDFQWmpReWVDVXlSamh1V2pkRmExZDJPR2g2TkZZeldGQnljbXd3UzJkclVVSlZXVE5ZZWtSQlJsYzRhRVF5UkVaNVVYTjFOMFJyWldVbE1rSjBNbE00Ukc5a2FWTnBUbnBPVFVwTVFYUjNVa1V3V2tjeVlsUTNTaVV5UW5sbVVEaG1RbEpNTkV4SlpFeEhhbkIyWWtodU5tVnpibHBwVEVaWlJVMXlXV2RzSlRKR1QyNXZiVEJGVFVneUpUSkNVV0o2UWs5aU9HcFdSemRCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1ad2FXTmhjMkV6T1MxelpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MVFhV05oYzJFdE1USTNNek10WkhBdVpYaGw=

http://www.chucklebestapp.com/WVl6OTRQVWMyZW0xdVlXMWlSM0prZEhsUGVsVjBSVTB5VEhwSlYyWkNiR2g2ZFVkVFJFTllkMlJUVDA0eEpUSkNTU1V6UkNaalBVeFRVa1ZvYVdGNFlXNUhTRTAwYWlVeVJua3habGt6VVVoVVpFczRZV2RWT0hSME5WZGFRbkZPTTJWUFpqUlVWMlZGZEhnek4wZEhZMmxFTUdkUldIUjRhVXNsTWtKb01rWlhTREZaVm5SVFZUaGxUVXBGZEhsVE5UWkdNMmRDVjFsVFJqTndZbHBJYUZodWJ6WlNPVUZyUzJkc1FqZGpSWHBVY0RBME9XRndhbFIxV25SNE5XeGFlak0zYVVGc1duWlpWV2xuWkdGSmVXY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1aM0poWm1scllTVXlabkJwWTJGellUTTVMWE5sZEhWd0xtVjRaU1prYjNkdWJHOWhaRUZ6UFZCcFkyRnpZUzB4TWpjek15MWtjQzVsZUdVPQ==

http://www.packagesoftwaretowers.com/WVl6OTRQVnA1WWtRelNuRnhhMWswUWtjM1EwbDZXVkpTWmxSd1dsTnNlVUpGVWt0Q2QzWkdUWFUwZGtkSlRVa2xNMFFtWXoxVGNGUWxNa1pvYVU1bkpUSkNiRVlsTWtKWlZ5VXlRbVZPWlZaRFRGRWxNa0poSlRKQ2NYaERUMnhMVFhnNFpYbHFXR3M1WjFKcWRWcHdXamhWVFZWME9XRklUa040SlRKQ1pISkRSMjFFY21KclRtUlJOU1V5UWs5TWFGUkRUMU5OTUV0UVJEZGpiVE0yY2lVeVJrUTJaSFJVUzJGYWFqZ3dSRWhPUldOS1JERlpTMFJXVTNCTFdVSXdhSEZ1Y0VJbE1rSmhWV2xvSlRKR04wUmhOMll3SlRKR2FGUTRVa1ZsYmxKQldIY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1aM0poWm1scllTVXlabkJwWTJGellUTTVMWE5sZEhWd0xtVjRaU1prYjNkdWJHOWhaRUZ6UFZCcFkyRnpZUzB4TWpjek15MWtjQzVsZUdVPQ==

http://www.chucklebestapp.com/WVl6OTRQWGsyZUhGaE5tTkVhVVE0SlRKR2VGTjVhbWh5U3pWQmJURlBlRGRHTmtaaU9HWjVaRGQwU1dGelRGSlhNQ1V6UkNaalBVUlVOekpTWnlVeVFtbzRWVGR5VldaUGVXNXJUMWcyT0VkRFFrUmxNR0pNVm1KM1lrNUVVbFF4ZUhFM1RHazBiREZtWm5wTE9XVlBjalpIVm0xUVVpVXlSbXRaWkdGSGVEUWxNa0pPY1hCTVRtcHlaM0JtT0hRMFkzbDFOWE1sTWtKWWRGbENVbkU1U0ZCSWJVMTNOblJIV1c0NVNqVkZNMUZhYlVoQlIyTlBWM2R2TUd0SWRHUjFlWEZ5ZHpCNGEyVjBiR0ZzWmtJbE1rSTFjalVsTWtKdlp5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWm5jbUZtYVd0aEpUSm1jR2xqWVhOaE16a3RjMlYwZFhBdVpYaGxKbVJ2ZDI1c2IyRmtRWE05VUdsallYTmhMVEV5TnpNekxXUndMbVY0WlE9PQ==

Latest 30 of 71 download URLs

Remove picasa-12733-dp.exe - Powered by Reason Core Security