shadowfight2_downloader.exe

Fapebepin

Mode Quality (Alpha Criteria Ltd.)

The application shadowfight2_downloader.exe, “Fapebepin Setup ” by Mode Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.vaultsconceptsapps.com.
Publisher:
Tobu   (signed by Mode Quality (Alpha Criteria Ltd.))

Product:
Fapebepin

Description:
Fapebepin Setup

MD5:
f6686271a9e0bc907874897af0623cad

SHA-1:
5891683b7886c887de5c8f2dcaf0736856ea41a1

SHA-256:
3895849e8a2807be306d645ff6757e93ec4076689c1a51e513ea7dafda851eab

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/27/2024 6:36:28 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
17.1.8.10

File size:
933.6 KB (955,968 bytes)

Product version:
2.8.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\shadowfight2_downloader.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/7/2016 4:37:46 AM

Valid to:
8/3/2016 9:20:26 AM

Subject:
CN=Mode Quality (Alpha Criteria Ltd.), O=Mode Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F7B537910FF19F9FCEA90DA601703349

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9365

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file shadowfight2_downloader.exe has been seen being distributed by the following URL.

http://www.vaultsconceptsapps.com/hRPFfXeNVQlpOZh6uw9s_omYoL0BuVlDJqVpBEzFH1SHGehK7DiN60_kwFYdslRrqqzmvjC5zrqWuJIu_zdFGKAEqXGwtSQZV7DOiU9Ma1L1Ql0S0krKAEGAREa0mtP3anSnusx_6JZvFlzktYuYbcKI77z6kWk0qZx5RC8GNtWPTN5w3SPyfhLO 81Ylf8x5ScepquU_Clxfyk0tyQUqSHZuI5WbjqHQrB1IxuqVNo7ePVPg3od1anslWi_6KHFe1XESImwOCbiaSlz0SzWJNgTG3bY0 5q74dFQv7R68cSjQPOhFWOyOEf0EGYNxl1060Q6LTlG9T 12JxGbzuUXx3yjZeThN6a4mQ2hpjl9I_Y5VsiE3gL777nJ4COq0lGPJAnuZl4rMtog9krWGmZrs7AHWrfXtqlnhz RJEEKIUK5RsV2YHPCwqFGk2cCDeY19kYsuKNIAdRxbBY8JaVd_LKUeEKNgJIBilXvQbe_f9wTGknETFwB6tqyTHCyikdXpZnAODpidCvc P5EUCVKVaG 9mLUHMwCb Zlj2Wh4bdJuSuiA cXp7Cv9YrBOCP mVSqg 9o0x_quXqYoZxSev4GiRQBdWWIbsIZ7wVuxV0ry_NXA=-GyoAAMQuF5svWSAJxQko5rZ1IZLMopDGNg_Ejbt9TzoBxFoOet4HC6tFUQ8=

Remove shadowfight2_downloader.exe - Powered by Reason Core Security