skype-13018-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application skype-13018-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
d4fbbbe4c7571e3c3758ab688d7ab00a

SHA-1:
1317cdf1bba84f232d196097d3a6306a68252d7f

SHA-256:
788987f155d8a98b1b9bdb5a41a4380444a4191eb989c9101b57caa27fcaa091

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 6:55:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.9.19

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\skype-13018-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:vCi46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:vrrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file skype-13018-dp.exe has been seen being distributed by the following 33 URLs.

http://www.clearuniversecapital.com/WVl6OTRQVU55VjJSYVlqVkpieVV5Ums1UGVrRWxNa0oxWnpGaVl6aHhhVFZuVmxCT1VFSkJWRUpETjBSMWJrRjFNa1pGSlRORUptTTliVTR6SlRKQ1VXTkxVVUp6YmtwbVowVllZVXM0YWtnM1JIcHRVekZOYUZka1drbHJhWFU0UzA1TlpsTnllVVJxTnpaWWNuaGhNSFJLWVVrMFRuQWxNa0pST1d4alVFUXdhaVV5UWtGVGJWVkliSG9sTWtZMFUycGlPSEZWTjJSMWMzVXpabEpRZERaeGVuQnRhRmxFVVRSVU9WQnhXWFJLUW5OMWVXRTVKVEpDYTB0WlpuWlNUU1V5Ums1dVpVOW9TMlJwZDJsbmNtWXhTbmgwVmxGUVdFbFJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTJFbE1tWWxNbVprYjNkdWJHOWhaQzV6YTNsd1pTNWpiMjBsTW1Zd1ltUTVaR0l3TjJFelpUTTRNRFUyTVRVNVpXTXlZMk14WmpRNVlUWm1ZU1V5WmxOcmVYQmxVMlYwZFhCR2RXeHNMbVY0WlNaa2IzZHViRzloWkVGelBWTnJlWEJsTFRFek1ERTRMV1J3TG1WNFpRPT0=

http://www.bundleflashapps.com/c?x=DLWywh7IbwZ1YiUH3gGYtK3jHF4wiR6R6hDJ5zmews8=&c=ne2lSGnybU/dmlhjVqZYzAgD7ZVdLHeWS8eSM 2qK006OfzW2LwIa7U9ORpowKRJJB0P9F1GN9sYrMmE1SfO9mug2JCPR3P2iqbL66gmI HDIcI6IfrpfPR QCQhA vd1plhR nI3yvclmK4NzC/fzYrAmDnvdCF6b9Q1A7zSxk=&e=0&fallback_url=https://download.skype.com/.../SkypeSetupFull.exe&downloadAs=Skype-13018-dp.exe

http://www.bundleflashapps.com/WVl6OTRQVzkxWkd4UlYxVktTemRRYjAxbWRUWlRUR1pyYURVbE1rSlVUakJrVEhoamNYSlVabmhWUmpkV2JGVndTU1V6UkNaalBUaHpTVVZGUVU1bU1XaDVaWE5tY1V4cmFXOXpkbTF5Y1ZFeGVqQnlWRXNsTWtKWFREaENZbVY0TmpjME9WTk9hSEpRTkdKV1MwODFiVGwyY21FMlQwNU5OR3RGUmtwdmFWWjJaemgwWlRNMFRtSkJZbmxtYW5wRlQzcFBPR2szU201clR5VXlRbWRpZG5wc1FqbEtaV01sTWtKM05IZFNjM2t5VmtjMGMxZGhja3BIWkZGRVZURjNVbWx4VUdGV2VEWXpWblkzYzNnNGRFcDNRU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEJ6SlROaEpUSm1KVEptWkc5M2JteHZZV1F1YzJ0NWNHVXVZMjl0SlRKbU1HSmtPV1JpTURkaE0yVXpPREExTmpFMU9XVmpNbU5qTVdZME9XRTJabUVsTW1aVGEzbHdaVk5sZEhWd1JuVnNiQzVsZUdVbVpHOTNibXh2WVdSQmN6MVRhM2x3WlMweE16QXhPQzFrY0M1bGVHVT0=

http://www.contentdownloadmega.com/WVl6OTRQVk1sTWtKaVNUWnBPR2RoWldJME1uaGhWakZFYkVRM05taHFVR05DTTBKeFRVWm5NblYwTjA1Tk9GUjBUU1V6UkNaalBWSjZVMHhsY2tzbE1rSklibll3Um0xUFdYSWxNa0ppWmtWaGVrb2xNa1p6YmtKUGN6TnlNR1pPWkZCSFQzTkNURU53ZVdkNFEzQnlhbG8yUldkNVZtSTNla3RhYW5NMFEzZzJaell5UTNCTGJWcFJPVUZIZUVoWGEwaG1UV2tsTWtack16RktTalJpTVVOS1RpVXlSazgwZDJzbE1rSjZSaVV5Um5Nd1NVdzBVVk52TUZwbFlUZFRPREFsTWtaMlVVcEdVV2QwVVhGWWMwNVZaMXA2WmtsUWJEVllUMEVsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG5OcmVYQmxMbU52YlNVeVpqQmlaRGxrWWpBM1lUTmxNemd3TlRZeE5UbGxZekpqWXpGbU5EbGhObVpoSlRKbVUydDVjR1ZUWlhSMWNFWjFiR3d1WlhobEptUnZkMjVzYjJGa1FYTTlVMnQ1Y0dVdE1UTXdNVGd0WkhBdVpYaGw=

http://www.contentdownloadmega.com/WVl6OTRQVUZpWldKYVIwVjNTbEpvZW1OR01HYzJOMmhPY0hVNVkzaG9SSFExT0RJbE1rWnBRMUp4VFhGd2FrMU1PQ1V6UkNaalBYQnllSE5sTUVKUFF5VXlRbGtsTWtadFptNVVSM29sTWtKVE5XWWxNa1pXV0hCMmJIWmFkMGt4YlZoQmJXZFVkSGxzYm05NFpWb3dZM1pNT1hCdE9VcERURmNsTWtabE0xSlZUakUwVUdOb09HVllOVVFsTWtKblJXbGhVMkZIY1V4VlpGWjBOMXBOVG14UmRERlhTU1V5UW5kc1pteDFZMnR1ZVRsTWQxcHhNRmRPYTNGc2IyNDFURTlxZUhSNFZISkNkWGxQVlV4SWRTVXlSbHBMYjFwamNuRkNKVEpHUVNVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhCekpUTmhKVEptSlRKbVpHOTNibXh2WVdRdWMydDVjR1V1WTI5dEpUSm1NR0prT1dSaU1EZGhNMlV6T0RBMU5qRTFPV1ZqTW1Oak1XWTBPV0UyWm1FbE1tWlRhM2x3WlZObGRIVndSblZzYkM1bGVHVW1aRzkzYm14dllXUkJjejFUYTNsd1pTMHhNekF4T0Mxa2NDNWxlR1U9

http://www.presentheartapplication.com/WVl6OTRQU1V5Umxob2NrUnhVbVZUT1hWQ01VOUdSa1V5SlRKQ1pqQnhjV0UwVDBRNFlURkVaV0V4SlRKR05GaFhjR2QyYjJzbE0wUW1ZejFYYzJjMVJETTJSVzVrTW1KT2FWbHJRWFJOYldaclJDVXlRbUptVVVWcGVFMW1lVVF6Y1VKYWJFbENXRnByTmpGSWExQmhORXROUmxGcFFrTlFPR1kyVFRkb2MyRWxNa1o1Ylhob04wNVNZVUpWTXlVeVJrTXhRMVY2V0dGSVVtZEZjWE4xVGpoVmVVcEtiVEZSZGt4T1JqaHZRVFF4Vm5NNFVVUXdjRGR4WlhKWE1uWjVPVmRRZEZCb1IwWjZkMHhLWlU1aVRrTnZORFUxYlZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpZU1V5WmlVeVptUnZkMjVzYjJGa0xuTnJlWEJsTG1OdmJTVXlaakJpWkRsa1lqQTNZVE5sTXpnd05UWXhOVGxsWXpKall6Rm1ORGxoTm1aaEpUSm1VMnQ1Y0dWVFpYUjFjRVoxYkd3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05VTJ0NWNHVXRNVE13TVRndFpIQXVaWGhs

http://www.conecptbulklaboratory.com/c?x=WA4UkHB546g5culi1LV5V4wdpyc9 6H87FE1lk8UyoM=&c=uQdH0O9dqj0DXvbg8LAVo5Vco8N8gR28nwBWA6crA/Q455yUfR6 pPROImL0zMdVi Y8GkiRJAFYteZKpgBKMqQNYjNHVc2F1QReMXu4SCKxZgNXvQKhClE6MXVseGpG9OcWWko5uEuPGJX7IPEIMQ==&e=0&fallback_url=http://download.skype.com/.../SkypeSetupFull.exe&downloadAs=Skype-13018-dp.exe

http://www.todaymetabundle.com/WVl6OTRQVkZNVldaamFWaHdKVEpDVFVsQmFVaFhOWGR3UmtSMFZWcG5kRk4yWWxKSlNtVlFOa2M1WkhGU2FXcDVXU1V6UkNaalBXRnVUMGhMYkhjMVFrMWxlVEpMT0VWdkpUSkNUVzBsTWtKQlp6ZHdWM2hETjBwTFJIaGxNR3RVYVZCTllVbG5kVTFqYWtWTGFqRTFUSEIwU1hKaGFuUkVRWGN3ZEV0MlIwZEJaSEJhUzBGek16ZHNiRVF5TkZOa2IxSjZKVEpDYzFORU1IQlhTMjEwZHlVeVJtWkdOMHRSYVZGclIwZ2xNa0o0WWs1S2FITkxURFpJVGt4TmEyUnVkVVJJUlVWWFRHZzNaWE0yUjNSaWRHUXpZMHhNWlZFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpZU1V5WmlVeVptUnZkMjVzYjJGa0xuTnJlWEJsTG1OdmJTVXlaakJpWkRsa1lqQTNZVE5sTXpnd05UWXhOVGxsWXpKall6Rm1ORGxoTm1aaEpUSm1VMnQ1Y0dWVFpYUjFjRVoxYkd3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05VTJ0NWNHVXRNVE13TVRndFpIQXVaWGhs

http://www.stockbundlecentral.com/WVl6OTRQVlpCYzNwS01HeFlVR1pMY0ZkSFJuUjBhV3BpZW5SNVRUUm1jVnBJY0ZSc2EwSmFiMVZqZFVsdGRsVWxNMFFtWXoxbmFHWm9aamRYVFdWWmNVNUhiRko0YVRadmFEZzVWa1ExU0dGdFRtazRiSEF6U3pGd1Nrc3hUbU5NYlhsTVowTkhlR04yYjAxaU5WbFFNMU5zTnpkRk5GaFZSbmgyVm5SQ1NGRktWR2x0U0c5QmFHeDNWakpMVDB0UmJHWnVVRlJvVW1GaGNrazBOa3BwVTJsbGRHcElZV2QxUXpKMVFVVndVSE5xU1RGa01VeDZTbVJSVldWRFFrbzRkbGhFVFRkTmJXNWpUMEVsTTBRbE0wUW1aVDB3Sm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3Y3lVellTVXlaaVV5Wm1SdmQyNXNiMkZrTG5OcmVYQmxMbU52YlNVeVpqQmlaRGxrWWpBM1lUTmxNemd3TlRZeE5UbGxZekpqWXpGbU5EbGhObVpoSlRKbVUydDVjR1ZUWlhSMWNFWjFiR3d1WlhobEptUnZkMjVzYjJGa1FYTTlVMnQ1Y0dVdE1UTXdNVGd0WkhBdVpYaGw=

http://www.tagtowerscapital.com/WVl6OTRQWFIzUnpKUlluVWxNa0paUXpGSlZHdG5TbmhvVTNFM09VMWtTbXhGVjFSWlNUQXdWek5QTW1KVlkzaHlPQ1V6UkNaalBXcFdSbWxRUkd0YU56VlJWMVp2TkNVeVJqVXpiekZwZVVsSVZtWjJVWFJGTm10TmR6RlJRbU5ZWlZWa2JuY3dVVzlDU3pCVE1GTkZSekZSTlV0MU5YQlBVVzVqWW5KUVNubFVSWGczYWtaWVFrc2xNa1kxTTNaRGIwbFpaa1pPT0UwM1RrazFPRzlCVDI1Q1lVSnlXa2RSYVhnbE1rSjNKVEpHVVdZeFQxcGtaRTVHU1cxU1Z6SnZNVEZzTURCTFp5VXlSaVV5UWtNME9YTk1OMk5KSlRKR2RGQkJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjSE1sTTJFbE1tWWxNbVprYjNkdWJHOWhaQzV6YTNsd1pTNWpiMjBsTW1Zd1ltUTVaR0l3TjJFelpUTTRNRFUyTVRVNVpXTXlZMk14WmpRNVlUWm1ZU1V5WmxOcmVYQmxVMlYwZFhCR2RXeHNMbVY0WlNaa2IzZHViRzloWkVGelBWTnJlWEJsTFRFek1ERTRMV1J3TG1WNFpRPT0=

http://www.tagtowerscapital.com/WVl6OTRQVzBsTWtaRE9HOU9la1k1TnpsM2VYaHRNVFpKTjIxMk5VRnRWRGRWWVRoeE9EZDFKVEpHZUc5dU9WUjJaVWhCSlRORUptTTlWazlCYW01a01tOU5aRXB0V0ZORWRuZFRjSGRSZDA5UWNHSkNOVmRwTmt4MWFHOTZabU14V1d4RlZYWlJVMGh1UW5ob1lURmxkMEpyUVdweEpUSkdPVFpZUmpObVVrb3lZMk41YkRkeFFrOUVSMWxhYTFFMFEwdGhhMmRYV0dWM2VFUnFUVk5tVlc5Vk9YWk5UMWhyU1RONlJteGFVaklsTWtKb1JURmtUbVEzTjNwVWNuaExSbEZKT0dsb2RGazRVRFZXSlRKQ2RsaFFWVFZuSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0hNbE0yRWxNbVlsTW1aa2IzZHViRzloWkM1emEzbHdaUzVqYjIwbE1tWXdZbVE1WkdJd04yRXpaVE00TURVMk1UVTVaV015WTJNeFpqUTVZVFptWVNVeVpsTnJlWEJsVTJWMGRYQkdkV3hzTG1WNFpTWmtiM2R1Ykc5aFpFRnpQVk5yZVhCbExURXpNREU0TFdSd0xtVjRaUT09

http://www.clearuniversecapital.com/WVl6OTRQVFZyV1VVNWVGSXpOV2dsTWtaaVJsQk9KVEpHT0ZwcVdHUjBNMDVoVGtadWVtMW5NakZzUmtKcWRUWXdSM2RaSlRORUptTTlkVEp6TTI1eVZ5VXlSbTl6WjFKa1VYSjVSekVsTWtKa1ZVNTBWV2xhYjNGSFVFWmpaVlUwYkhNelJGTnNZa0ZUTWpkRVpWbzRXblJFTWs5QlNFWkhabkIwUkd0alQyRkdXSFpqZDFOUmEyOXRTMEZ2YjJKTWRsWlpiVE0yUlRZMlpITnpZU1V5UmtjemVuSldKVEpHTmpoeE5VUnlTa2hQVGxwd1pqTnZlVUpIVVUwemIyUm5NV2xKTURFNE5EVkNNRmh6ZFU0NE5qTlNlRU5NV2tFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd2N5VXpZU1V5WmlVeVptUnZkMjVzYjJGa0xuTnJlWEJsTG1OdmJTVXlaakJpWkRsa1lqQTNZVE5sTXpnd05UWXhOVGxsWXpKall6Rm1ORGxoTm1aaEpUSm1VMnQ1Y0dWVFpYUjFjRVoxYkd3dVpYaGxKbVJ2ZDI1c2IyRmtRWE05VTJ0NWNHVXRNVE13TVRndFpIQXVaWGhs

Latest 30 of 33 download URLs

Remove skype-13018-dp.exe - Powered by Reason Core Security