powerpoint-viewer-12204-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application powerpoint-viewer-12204-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
a68f100fcae6c50009fe8b72f6b70327

SHA-1:
3052a7f7ec35c4afa58c6ad1d05ebe1aca1642bd

SHA-256:
55bcd98c5d73d2f5183fd2bcca584b4d5dfbfcf55726d0f0a53d4f7c3924c201

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 5:52:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.10.1

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\powerpoint-viewer-12204-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:xrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file powerpoint-viewer-12204-dp.exe has been seen being distributed by the following 30 URLs.

http://www.contentdownloadmega.com/WVl6OTRQWFF4UVhCUVMzbFhibEZISlRKQ01VTldRbWxNUWtOUmJVZGljRVpPSlRKR05sbDNiVGROU0VSWE5HOUJPRVZySlRORUptTTlUa1J5V0NVeVFqVlphMWRoVDNoalp6SnZTa1pvTlhSVVEzVkhla3BtUkRseE55VXlSblYzUWtOQ016YzJSazlJY2pKUGEzRXpTWEJyTUVZNFJXcHdhMFpIV0hJNWFXdDRPVEJxV1VKT0pUSkNXSEJRUzNkYWRETTRRVEpFVURCYWMzTndXR1JPTlc4eWEybFpSRkF4V1RSRGN6TlVVRXhIYVVWalYwWTVUMFZVVjFWRlpVUjZialpIUmtseVZuVkhTWFpMV2xOTVZWTnBjMHRCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG0xcFkzSnZjMjltZEM1amIyMGxNbVprYjNkdWJHOWhaQ1V5WmprbE1tWkZKVEptTkNVeVpqbEZORUUxUmpsQkxUSXhNRVF0TkRSQ055MUJSRUV5TFVZME4wTkZNREExTkRGRlJDVXlabEJ2ZDJWeVVHOXBiblJXYVdWM1pYSXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHOTNaWEpRYjJsdWRDMVdhV1YzWlhJdE1USXlNRFF0WkhBdVpYaGw=

http://www.headcycleuniverse.com/WVl6OTRQVE5vYTBKVGR5VXlRblZSUkhGWmFVaFlTVmxWWlNVeVJtbFNaalZFUzBsWVVYSk9kMjFYY1VzbE1rWnplVkpMYWpnbE0wUW1ZejA1T1NVeVJqWktPRkJrWmtGTGRIQkRUWFZEUlRGVVpWbHdXamhvSlRKQ1ZtZFFZM2RSZGlVeVFsVnFXamR3VW1GRUpUSkNUMFI2UXpCSVJHY3dSamNsTWtKVWJIWTFXREZCTlVOMVluSlVlRTlHWVZZM01ucHNKVEpDWm5wVVkwZ2xNa0p1U0hwWE1YcEJVREF4Tms5UU1sRlpWVzFvWWxSSlFsRndRek5DWkZOdFoxRm9ORUpyYmxwaGRHdHhUM2hoVjFVelVuWmFlRXBNYkVWSmQxRnlVR3B2VVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aa2IzZHViRzloWkM1dGFXTnliM052Wm5RdVkyOXRKVEptWkc5M2JteHZZV1FsTW1ZNUpUSm1SU1V5WmpRbE1tWTVSVFJCTlVZNVFTMHlNVEJFTFRRMFFqY3RRVVJCTWkxR05EZERSVEF3TlRReFJVUWxNbVpRYjNkbGNsQnZhVzUwVm1sbGQyVnlMbVY0WlNaa2IzZHViRzloWkVGelBWQnZkMlZ5VUc5cGJuUXRWbWxsZDJWeUxURXlNakEwTFdSd0xtVjRaUT09

http://www.contentdownloadmega.com/WVl6OTRQV0pZUldWRVpGZzRKVEpDTm5KdWVYVmxUbkJsUVZoMVRHcEViakUyTjJSNWF6aFVSMVYzYzNaaWFFMW9ZeVV6UkNaalBUaDJZMHhFVFVVMEpUSkdlbWxWT1hFbE1rSWxNa0ozTTJKclpGSjJUV2xoT0haallWWnVhbmh2TW1Ka2FUbDZPV3hVYjJ3M1NuZG1PWEJJYVcwNE5XaEtZblZzVW5KdmNWRlZSMU5KVmpJeE4wSlRiR2RsTkRSRGRFcHhiRWhwUmtoUFoxZzRPREZaVUd0QldVOTNjVGxDY0RoV1lUaHdia2xETlVrMFNVcHliM3BXUkVZM2FISnJjMnhIVUdOV2QyVlBNMjFSWnpNNEpUSkdSM2RCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG0xcFkzSnZjMjltZEM1amIyMGxNbVprYjNkdWJHOWhaQ1V5WmprbE1tWkZKVEptTkNVeVpqbEZORUUxUmpsQkxUSXhNRVF0TkRSQ055MUJSRUV5TFVZME4wTkZNREExTkRGRlJDVXlabEJ2ZDJWeVVHOXBiblJXYVdWM1pYSXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHOTNaWEpRYjJsdWRDMVdhV1YzWlhJdE1USXlNRFF0WkhBdVpYaGw=

http://www.bundleflashapps.com/WVl6OTRQV1ZrVW1WWE1EZG9aMWxDWkVsa01EQXlObHBoYWlVeVFrVnRORzU1Y1VSMlNGRWxNa1p5SlRKR1dHUnljbWhaU2swbE0wUW1ZejFvT0NVeVFrdDJTemhvY0ZWbGFVdEhXVXhtU2xaM2NuSk9WWFY2UmlVeVFqWm9hWGxRVVZORWIwMXNVRmRhYzNoRGNIQnVabFZyWm1SeFMyeDFiMEZXTUdkNWJYSnpUVXR4U1ZFMk5WZERhbUZuTmpWb2QzRkZiVUppVkdwM1UzSTRPRkJRWlZkQlZrcDVObmN6UjBScmQzZHFhMEpSYzNGS05EUnlVVzFSUTBodGEwOGxNa0pZUjFOUFQzWm9jM2xGY2xweWVtVjRSalkzT0VFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbVpHOTNibXh2WVdRdWJXbGpjbTl6YjJaMExtTnZiU1V5Wm1SdmQyNXNiMkZrSlRKbU9TVXlaa1VsTW1ZMEpUSm1PVVUwUVRWR09VRXRNakV3UkMwME5FSTNMVUZFUVRJdFJqUTNRMFV3TURVME1VVkVKVEptVUc5M1pYSlFiMmx1ZEZacFpYZGxjaTVsZUdVbVpHOTNibXh2WVdSQmN6MVFiM2RsY2xCdmFXNTBMVlpwWlhkbGNpMHhNakl3TkMxa2NDNWxlR1U9

http://www.bundleflashapps.com/WVl6OTRQV1E0YzFwdVRIaHNlbWhqVkhWMGVrNVZjRGhtY1RWMFVDVXlRalZQYjJweVJGTXhkbm81TTFCaE9WaEVVU1V6UkNaalBYZDBKVEpHSlRKR1ZWVmhObmQ1UVV0NVduUkpaV05QVm5rbE1rWnFZblZHTWsxaGVIUWxNa0lsTWtKVVRFeG5OM2gwYVRkNloyMTRZbFJIWWxoWGJsTmxhWGcyT1ROT1NtMXpWalpLY1U5R2MzbExZbEl4TVhsQlltTlpObUpZYmsxdFpYUTBiR3BXVW1oMFNWTm1TMGRGWWtoT2NWcFlObHBMU21GWmFtWm9lVk1sTWtZMVdIRkJaM05tWkVSTmRWbG5kVzh4YjFwWWNYaE5aa1pVUWxkMmR5VXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWmtiM2R1Ykc5aFpDNXRhV055YjNOdlpuUXVZMjl0SlRKbVpHOTNibXh2WVdRbE1tWTVKVEptUlNVeVpqUWxNbVk1UlRSQk5VWTVRUzB5TVRCRUxUUTBRamN0UVVSQk1pMUdORGREUlRBd05UUXhSVVFsTW1aUWIzZGxjbEJ2YVc1MFZtbGxkMlZ5TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJ2ZDJWeVVHOXBiblF0Vm1sbGQyVnlMVEV5TWpBMExXUndMbVY0WlE9PQ==

Latest 30 of 30 download URLs

Remove powerpoint-viewer-12204-dp.exe - Powered by Reason Core Security