sopcast-12954-dp.exe

Rukimakin

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application sopcast-12954-dp.exe, “Rukimakin Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Rukimakin

Description:
Rukimakin Setup

Version:
3.7.4.5

MD5:
e5137c2456786957eae05e92dab29197

SHA-1:
28578e8cc7f01f222ee792530529ea7ac8602de9

SHA-256:
bdc492cb54076656c8bc600ff9f5e6900be12a6f12b1d0e66ee6d20d509c9f77

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/1/2024 4:31:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.11.7

File size:
960.6 KB (983,624 bytes)

Product version:
1.2.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\sopcast-12954-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:9Ci46vIpWeGEvHstSIgFnM2MXLk03/hNcQQicg6pxiEW8:9rrwwXEvHstlgJM7k8DNcggxC8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file sopcast-12954-dp.exe has been seen being distributed by the following 50 URLs.

http://www.tagtowerscapital.com/WVl6OTRQV3RPVGxwWWVrUlhSbVIyV2xoU2NEVm9lRlJ6Y21KYVZVeGxlRmhXTVhWeVlXMUxPV3B2YlNVeVJrUldjeVV6UkNaalBXbFlhbmt3ZUdWTWVGUTNXU1V5UW5Kd09WUjZkbE13V2lVeVFrWlpORlJ4T1ROUFVXMDBKVEpDVEdkRlZIVnBVSGRGU1RaaFV6WXphVUo1VVU5RVZHdEljMHRwU1dOUFdpVXlRazlTUlRaelJUVm1lbXh0VUNVeVJtTkZUVE1sTWtKek1tOVpNM2h2YVd4b05uaGhia05FYXlVeVFrbHdZa3RYU2pJelVWQnJlRFpCY25GNlNHVnBNV2xDYlRaMWVuQmpZVkZyYVd4SWJXVTNUMFZpVURoV1YxUjNKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aVGIzQkRZWE4wTG5wcGNDWmtiM2R1Ykc5aFpFRnpQVk52Y0VOaGMzUXRNVEk1TlRRdFpIQXVaWGhs

http://www.tagtowerscapital.com/WVl6OTRQWEF5UkRaVWVqSTVKVEpDUjBWVGJ5VXlRbGd3ZEdzeVRFVk1Obk5aUTFwNWRuY3dObk5HUWxwMlEwbEVjVU5CSlRORUptTTliRWh1U2pSMVJUQTNXVVJMTWtsT2JESmtXQ1V5UWpKUVdtNXdhVzA1WjNka1MwRlVSWEkyUm1oeWR5VXlSbEZOTUZaaUpUSkdOR1JOWm5wdFFUVlROblUwVEc1TmVtWm1jaVV5UW5GNVkxWkJPRWxWWW1adU5GQndjVzkxWTNveU0zUjRSRXhWUWtFemNsWnRlRXRTZDJZMWRWWXdWMU56U3lVeVJpVXlRazFyTTBwVWJFaFlUMjlvZEdsd1kwTmxVWGx1U0hwdFMxcGxlamRIVkdONldYaFJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabTExYkhScGJXVmthV0VsTW1aVGIzQkRZWE4wTG5wcGNDWmtiM2R1Ykc5aFpFRnpQVk52Y0VOaGMzUXRNVEk1TlRRdFpIQXVaWGhs

http://www.tagtowerscapital.com/WVl6OTRQVFZyT0hSSE9ESk5kRE53UTFNbE1rWjNNR3hDYlhseGJ6SXdkV000TW5GdVoyeEVaMGR3UlRsRGFrRmpOQ1V6UkNaalBYSTRZMEpTYUZjMlNsbzRRVXc0VDNCTVZrTmFaME0zTlZGSWNHZGFOaVV5UWtKVGF6UXpaakJ2ZFhsVlYxVTVhMjVUVVdac1pUTlpiRXRCYXlVeVFuSktXalpNVURsa2FFTjJXbEZMUVhSUldrVXhZVFZ5YWxKRU5uTjVOM2RyZG1wT1QyOTBielZMT1hGbWNWQTVWVGNsTWtKS1NVUmlSR3BFZG1WdlZ6UnFRMnh1ZEhSNUpUSkdhVXRsU21FMlNIRTRiR0pxUlZBd1dsUkJRamxCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.todaymetabundle.com/WVl6OTRQVE42UmtGdWNrVlBWMFJDVkc5TGFERTFNRmwwUXpZMFIwbzRUMkpWUWpsM1FWTkVkSGt5UW1wMWMzTWxNMFFtWXoxT2FGSm1aekZVVm1wV2NsSnZZVXBGVW5nMFNGQjVNR1IwT1RNbE1rSlVjblpJZG5od2FGWmFWR1JUU1haTGFteE1Ta3ROYUVWSlIxVTVXbmtsTWtZMFRXTjNkQ1V5UW1Kc2FuQlNVRzFoTWpGT1Z6SlZZV3N4Ym1wd2VFZ2xNa1psZUhVNE5FdGxOVXR5VkRaRlkzUk1Oek5OYTNFbE1rWjZZbmR2WjFadk5tbzFSV0UyZVZOa1NHTTFZMGRXVVVaU2NHOXljVVJZYzBOcE1rZEpiREJSSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.todaymetabundle.com/WVl6OTRQWFJ5U0ZsMmNqVlBTMDVJVWxoVVFXeDFWWGR0ZFVwek1USmpXRWRLUVRCNU1XcHFTVGh6SlRKQ1dXZHVUU1V6UkNaalBYcFVjMFJQY21SVk5XNUxNa040UzBrMVdGWnFZbFpDVjNkSU1XSTRiRFVsTWtKVWFsVlJaREU1YnpsdGMxQkJkRlJ3Ym1kWlNFeFZNVWt3VmtJNVFYYzNhRFpVY1U5WE1EQnJZWEIyUTNjelptVlZjbVJxT1RGb2RVRjNlbEpqYUZkRU9HczVZalF4ZEVKU2FIaFpaSEZFU1ZaVVN5VXlRbFZxYVZCcUpUSkNSbWRWTTJGaGMzUjROa0pGVDJGdk5WaHZkbTFNYjFkdVNubHVkeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVp0ZFd4MGFXMWxaR2xoSlRKbVUyOXdRMkZ6ZEM1NmFYQW1aRzkzYm14dllXUkJjejFUYjNCRFlYTjBMVEV5T1RVMExXUndMbVY0WlE9PQ==

http://www.presentheartapplication.com/WVl6OTRQV0pIU1VORGRqSTNNRE5yWjIxWVRuTTFXbWhMZEdWblltcEVkR2d3Ukc1bVJIcExhamhETkUxT1NUZ2xNMFFtWXoweWVqUTVhakp0VUdGTVoyMWhVVEZPUWpoNFZYVm1KVEpHYkdNMllsSlViVTFyYTNnemRsY3hkRW93VWxkalZUUmtheVV5UWs5aU9YcFRORVJOWkcxbWFXVkxRamhKUlhWdEpUSkdSMEpuZFRGa2VXeDJPRFoxWVVSQ2JURk1ibTEwYjIxUU4wTk5iV3RQWjNCU1VrOVpXV1JISlRKQ2MyeFlkMHhWVTNWNVlUVnZkVlJGYUNVeVFuUTJkVFZKVURaeFNHSmxZVzQwZGtkaFNGSllSV3gzSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.tagtowerscapital.com/WVl6OTRQV2xNVTJWeEpUSkNRMHBGUjBwd1NFZzJWREZaZVVkWWVFdFpTbEEyZW05dU9TVXlRa3AzTTNaUFJqTnBibmxOSlRORUptTTllbmswYkVzMWFuSmFjbUpRY1cxRmQwWjVjbUZTUkZkelFXNUNPRzVuTjNOSE5WaGpNVUp3UjFScFVrSTVKVEpHUzNkaE5tbGFSSE5rYlU5dVZrSlJNbEY2ZFhwUU9GaHZRMWR6ZW5oNE1UUktaMHhHZVV4YVdUbHpOV2RMWTFjMFJrZzNXa0p2TW1sUGRWZFBNRmxPY25wSFJXYzFTM0oxWWtJbE1rSmFUbnBJUVZveVNHbFlTMHRLTlV4b1RHWkpTSEU1UkVsWmN6QWxNa1puSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.tagtowerscapital.com/WVl6OTRQVXg2UkVvMGRXSlBjWGxpTTI1T1JpVXlSbWg0WW1GbEpUSkdSazVMU1ZselZrdExSalpaZFhKMFZVeEhVV3BWSlRORUptTTlNbXBDWW5rNVVrOXhNVnB0WXpoSFFuSkRVbU00Y0VGYWNFZHBURk42ZW14eFoxaExSMUJEZWt4dVIxazBPVU5WYURaUk1XWnJUSEZKTlVrbE1rSTJWRVExTVc1T1pHTkVUV3R5UkdZNE1WcGhVRGRDWkZCa1NVbG9aMnRtZUhoaFkwNHhjVE5sVURsaFNsZDZlbTQxZFdsc2NWb3hValYyVVdSalNXSm5SMjQ0Y20xaWFHeHBNSFk0YkV4TE1uTlRjMDFhUkZkM1NsRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmxOdmNFTmhjM1F1ZW1sd0ptUnZkMjVzYjJGa1FYTTlVMjl3UTJGemRDMHhNamsxTkMxa2NDNWxlR1U9

http://www.todaymetabundle.com/WVl6OTRQVE53WVdsMVpWWXdVbVZSWTI5NlpUaGlOSE0zY1RsSFluRm1ha1JEYjJsUE1qUlBUMEp6WlVWcGVtY2xNMFFtWXoxMlpIb3lVRTlyVG1jbE1rSmxTM2xQUm5jbE1rSWxNa0p0V1hsMUpUSkNiVXRTUm5kTlF6bFBSRzFxV0ZsVGRtZFVaelkxYW13ellsWjRRM2RqTVc1VlkzWktTWEJPU2s5Q1REQlRORGRZZEdweFZUQmtZV3gyTUcxT1RYUjBSMDV3WmtKTFMyMWFVbUl6YTFkRFlWcEpSVGR1VTFGT2NFUnBOVEptTW5CeVJHSXpXVmdsTWtKSVJqRkRabmMxVmt4MlQySmFNVXRyY2pseFYzcEllWHBCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.bundleflashapps.com/WVl6OTRQVEZYVTFReFNVb3pNMUptVUZwWWRGTnBkRWhIWXlVeVJsa3hiMDE2UTBNbE1rWnZiaVV5UW1OYVRYVTNKVEpDUmxwUVFTVXpSQ1pqUFdoS05VTlFkRmM1ZW5oelVFOU1jR3hTWXpsRE0yTmhXV3c0YURSVVYwcG9XakE1TUdOQkpUSkdXRXg2UXlVeVFrUjVSalJwUlZWamJrZ2xNa0p6Y0ZOT1JVeEliM1pOWTBGb2VYRjViMk40V0RsQ1FuUk1VMHhYUTJSbFJEZGthbWxWVVd4UmNrMDRTMVpOZGtReFVHeGhaa00wUjJkMGNreFVORWxEU0dGalJIaFFVemx2VGtSV04zTlFNVXR2UjFvd1JUZzRVbFZOZEc5QlFTVXpSQ1V6UkNabFBUQW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWnpkRzl5WVdkbExtUnZZbkpsY0hKdlozSmhiWGt1Y0d3bE1tWnRkV3gwYVcxbFpHbGhKVEptVTI5d1EyRnpkQzU2YVhBbVpHOTNibXh2WVdSQmN6MVRiM0JEWVhOMExURXlPVFUwTFdSd0xtVjRaUT09

http://www.tagtowerscapital.com/WVl6OTRQVmhxVEZwRVVFTmFWRE5OYnpSU1puRktTeVV5UWtoSVVXVm9RVTFDYjJ4dVFsZzVlRmh3VWtodVowZFhXU1V6UkNaalBWaFBWbGhMTjFOeWNYSjFlV0l5VTNaMFkyOVJXVEZFUnlVeVJtWndVSEJMT1ZCTVJGSllPR1ZNZUdST2NYaEhkbTVJYkVoWVlXSTRUbkY1VERkVWFWTktUMDFPU1hkWWJXbDVjeVV5UmpFbE1rSjNOak5GVUZOUE9HUk5NMGxGUXpCRmVHeG5SM2c1TUZsa2NsaFViemRGU1RWbmRGZzVKVEpHVFhCb01FcHJRV04xT1doWE1IaHNWWGhWVUhCWllYUTNaVkJLTVVWV1VXZHFjV1ZCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm0xMWJIUnBiV1ZrYVdFbE1tWlRiM0JEWVhOMExucHBjQ1prYjNkdWJHOWhaRUZ6UFZOdmNFTmhjM1F0TVRJNU5UUXRaSEF1WlhobA==

http://www.clearuniversecapital.com/WVl6OTRQVkJISlRKR1preDJSakI2VEhaSU9HMDRWbk42TlhOTlVFaFFTWEpJTlhCRGJXSmpiSFZzUjBVMGFFVTJNQ1V6UkNaalBVdFZOV3B0TWsxTmVEVnFlbEl6YWpaemJHNXpNMmcxWlZGV1owSmlOV3h3YVdrM1FWcFZhbFZFYkd4VFZYRjZjMWRtVkZsSFMxSndRbGtsTWtaR09YVjZTMnd6UlU5TVNrbFhVbWRETUVweE9VUWxNa1l3VFRsTGJEbHdUR0ZMV21KWGIxUnBNSEo1U1U5VVYwYzFURlo0Ym5sVlpqQmtRVU5JVEdkQ1FrOXVhekJOTW00MmFHbzNiVGhJYUhZeU9FVlJaemRsY1VsblpHY2xNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5oSlRKbUpUSm1jM1J2Y21GblpTNWtiMkp5WlhCeWIyZHlZVzE1TG5Cc0pUSm1iWFZzZEdsdFpXUnBZU1V5WmxOdmNFTmhjM1F1ZW1sd0ptUnZkMjVzYjJGa1FYTTlVMjl3UTJGemRDMHhNamsxTkMxa2NDNWxlR1U9

Latest 30 of 54 download URLs

Remove sopcast-12954-dp.exe - Powered by Reason Core Security