roblox.exe

Bilocideh

SpeedyPrompt (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application roblox.exe, “Bilocideh Setup ” by SpeedyPrompt (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
SpeedyPrompt (Fried Cookie Ltd)  (signed and verified)

Product:
Bilocideh

Description:
Bilocideh Setup

Version:
1.3.4.5

MD5:
daf563d11ceb20eacafcc0328f73e6a1

SHA-1:
d91178678aede3165e00a2b5171c877121096318

SHA-256:
4730b3de4d540b89ad744a85f7ceb499fb4ee4bb1f5e00be0b942eedc834bae7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 3:28:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.16.19

File size:
940.1 KB (962,688 bytes)

Product version:
3.8.9

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\roblox.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 3:03:52 PM

Valid to:
5/20/2016 6:07:50 PM

Subject:
CN=SpeedyPrompt (Fried Cookie Ltd), O=SpeedyPrompt (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D77437A5B286B055B435AA59CB4BA265

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:QTZ/UNmp+F6Y/taNJPjYhVyP+a+8cMVTQAl/8nXoaY7Ab1a5Fnh2IUIjmm0ESlXL:QTZcQpqwJPP+a6IXUgAb1aXhxUT7lV

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file roblox.exe has been seen being distributed by the following 37 URLs.

http://www.quicktowndl.com/c?x=HxDIqYdjmCWmmh0xD PRYZ IbzdsW0V7I27/ZM51bzE=&c=O3L1ixfOoWL4oj5zvCk/nLjHiaBclR2ZAdKGkqVMezPuffTgLawCMuhE/trYck3O0sz 34 BiHCRyDWbD XFqtaJCZU2BZM1raZAjAZ 0HPTjKg2UBRtgk2LXySJR/1cvy5RTjH/A27qn RABRO8l/Uj8FQT40ptcvMWxCxCISs=&e=0&fallback_url=https://secure.innodl.com/.../roblox.exe

http://www.quicktowndl.com/WVl6OTRQVmxaUzBGMGRHWjRkVEJWUjBkdk9FWmlNRk5oTkVsRVoyVnhkbVk0UlZaVFpYcDBVVVZKWm1SQ2JuY2xNMFFtWXowMlRHeGhaV05uVlU5QlNITllaek5NYVVKV1RucHlXRXBpTW5SUmFuSlVTMU4wUkVseFlXMVhhbmczTm1aSk1VWk5Wa3hFY1cwM1RuWkpkMWt3YVhrMlVDVXlSbXhXTkc4eWFUZHlVR2hrVkRaQlMyWnhNR0ppYzJSbFZqbExORXA2UzNJbE1rWnlNbUZ3UTBJeldXbFhia2RKT0VKaGFqSkRka2x3VUdkemNFbFNiMU14UmxWelNqY3lOMUZSU2xSRmRtOTZiVWR6ZDNsM0pUTkVKVE5FSm1VOU1DWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNITWxNMEVsTWtZbE1rWnpaV04xY21VdWFXNXViMlJzTG1OdmJTVXlSbFZUSlRKR2NtOWliRzk0TG1WNFpTVXpSbk4wSlRORVVXbEJjSEF5YUhkVlRFbHZWMWRKVVdwZllrTjNkeVV5Tm1VbE0wUXhORFl6T0RNM09ETXpKbVJ2ZDI1c2IyRmtRWE05Y205aWJHOTRMbVY0WlE9PQ==

http://www.quicktowndl.com/WVl6OTRQVFp2Y2tjbE1rSkpiU1V5UW1wR1dHdHBRVlk0SlRKR1lsY2xNa1l4UzNGNk5HZDVhM1UxUkVwYVpISXlKVEpDYVhFeVZteDNKVE5FSm1NOU1ERkhhVEZNWVc1UlRFVkljRVZWT0dkVGRqRm9iRTlGVDFsWU4xZ3pRemxSTkVZMU5FY2xNa1owVG5nNE0zcFlXa2hTZVV4eGRsbzFNRmw2U0hCSE1rZFRXV2R4WnpCMVpGZEdkMDVCUVRReFRHTTRSVmhZU1ZsYVl6UkhaM1I1TURCTlRsbHBWeVV5UmlVeVJuWkpjMHhOUjJGS2IzTjNZVFZWYVZjMFNYbFROakJ1VVhJNVptTTVTazl6UldsRVJrdEZjWGgyTUVaQllrWlJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p6WldOMWNtVXVhVzV1YjJSc0xtTnZiU1V5UmxWVEpUSkdjbTlpYkc5NExtVjRaU1V6Um5OMEpUTkVWVmx5ZEZSMWEyRllTVTlYTlhvdFkyOUtjVWt5VVNVeU5tVWxNMFF4TkRZek5qQXlOREU1Sm1SdmQyNXNiMkZrUVhNOWNtOWliRzk0TG1WNFpRPT0=

http://www.quicktowndl.com/WVl6OTRQVGczV0VoRk1WWXpZV1YyVW1RbE1rWm1KVEpDVTIweVlrZFZjSGg1ZEhOeU5WQjNaQ1V5UWt0dVMyczFOa3ROVEVVbE0wUW1ZejFCTTFkMVRVVk5WMGt5WTNWM1UwMXJWSHBHUVRGQlJtaEJhbEk1YkZkVmJsSjJXU1V5UmpadVRqbFBKVEpHVjNONE55VXlRa1JrVjBaNVNXNVJUMmQyY1hkQmN6Rk1RMDlCVDJ4c1NYQnlkSEZKYVdFbE1rWkNaM2xNTjJKQ01XZHRORlI2WldSdGFWaDNNVlZQVFZCUVluVXpRMmxzVFROUlFXTlRWeklsTWtaeFlUVklhM1JYTlc5MVpUVnlOVEZvTmxJMVMybHBWMmcxWVVkdE4wbFJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTBFbE1rWWxNa1p6WldOMWNtVXVhVzV1YjJSc0xtTnZiU1V5UmxWVEpUSkdjbTlpYkc5NExtVjRaU1V6Um5OMEpUTkVkbXhJUm5SV2N5MW9TVFo2U0dwQmFWZHJWRzk2VVNVeU5tVWxNMFF4TkRZek5qa3hPRGMySm1SdmQyNXNiMkZrUVhNOWNtOWliRzk0TG1WNFpRPT0=

Latest 30 of 37 download URLs

Remove roblox.exe - Powered by Reason Core Security