winrar-5-11-32-bits.exe

Swift Funnel (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application winrar-5-11-32-bits.exe by Swift Funnel (Fried Cookie) has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as WinRAR archiver but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Swift Funnel (Fried Cookie Ltd.)  (signed and verified)

MD5:
46b96a592384dea447df4695d9de1274

SHA-1:
33f893fb8cc307a40faee072cc38e664ebefca24

SHA-256:
ae819e5a76b7c294f23355131c86490b7e7c781f72d47e23ab3419bf1e0180ee

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 3:49:51 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.184.224

ESET NOD32
Win32/InstallCore.RO (variant)
8.10714

K7 AntiVirus
Trojan
13.185.13993

Malwarebytes
PUP.Optional.FriedCookie
v2014.11.12.06

Sophos
Generic PUA DD
4.98

VIPRE Antivirus
InstallCore
34732

File size:
698.9 KB (715,672 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\winrar-5-11-32-bits.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/4/2014 3:05:02 PM

Valid to:
11/5/2015 3:05:02 PM

Subject:
CN=Swift Funnel (Fried Cookie Ltd.), O=Swift Funnel (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219222B1C3CFE5BB71BCB5117BC2A44FC6

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LT2aBIZBhDJLKc7NlZ2llDPkRZ1PZZrspGqNUHUBxvrQkgEm/XFjwHXwAbd2yZR0:LT2YIlw2yDMRdZrxqNyUB5rQkklwHvbK

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file winrar-5-11-32-bits.exe has been seen being distributed by the following 10 URLs.

http://d.baixakifiles2.com/?ic_user_id=254&data=MdaRZ4xWsxUuxhEBdfmJbxCL8HTpBy8Cp/iMStBv45EhMwDEOT487vEJUNuVWCmrArZ QQG53I05Nqzr41TY0irfB9VwbESpswBITIKB388EfJfZ6bdD EWVbFA9QB3KRNuQTieZZ8HgMRyzwTZeejvFbqsCU5CsttAJFZ2enF1SXlkx5dYJuxokP0u8C 4kJp1b8fPe7V5YYuCa9XPAkmXqCwWpZjN5D W40afGb2NW3LtJkaxy6g7iefKsWhHDP5 2CRNyEZBTAZAOjf5jFlWFDvmdwpouG0Xo6 hd oHkUxGDtbt7vsxpFrpIlniWLoQ68UQ0Q4fhMFIqdeXMgWwhpVrz2AgBk4cF2c4InhAQeZHbc7xetWoD4y/wqMblKYsfVDu3CMz8aXMBprt70io2zSTx1OrxH/z/JI006uPB3NKAe2Cx/jZgmW1D3ZiBQmxkatkyHQ V4wcO3AOGxt7FhoAyH71/bxO01Jai0IALMmF4i3GDPpIu /yUpGuGg62ghA8YkPG5H0tkmA vlcK9QSGU2GgXVu718rH1QI5tzkGqpuA t7pahyyri0MB63Pz3HJre1i8SVcz6yaBWwGD4Qt PYKlLfND1YMZT6c2Cjxp6hNiYOeRCSzgVNPx4qPVE wkulN5J1uc2fYmj58D9LkRtMfVE/5vSWr4XETSUwrA7Ku3TnQSzkflFL48&key=H27WitZE/ M1MctUJnbkhfW39qA/sSG qTuvEwCWiAd1TwwjGWA0sNAdljSfW8ORdPG6lyvbaCJeoovS3VGsHKCILCCjoR17SSfYnrD Gog7ITwFoeAYg9TPpZmxhn7Ws/tooYnpVSaCpzZ7r77UOihxsOyMgNQXYveOJfNrWr4lqHzxr0/J/.../jhzh

http://d.baixakifiles2.com/?ic_user_id=254&data=BeQDLzvJFsMEtXxkf3vNAnH288s7nBtLqDMygPE1BGOcju56SVDgaqyTUbsJrFNGHshZk6xscuA9Z7qHCrLLWbCnoNaeTkH64WLbpnuORqyDOQSneQXzm1QzVf8W6XY2FWJyWXnJ8Cykfzwhg975FX0 UUZprU/rCG8ZNt6iPqkzudgA2l3AUQequ0oPpo3MNZuAvj0VGyrdZJZw6efNI8C9gNx2vDZlP9lvPCGF9HY lgOF3faRKhYmeHjvscyOHC7PhXQbkvfX8f2DVUTbUG q4ngaEpdITu6tMXmzZpnh5pE5EgKIeKn60w4jvfxyAFMgbNhNKaUOWGy7GrCNLjaLN9ZdLr0mkoDGWS0nLBt9QZzYm0U7x9C38pAQmiYNWmaLVe9FpoAoSJcrnKUmdGoTfCzZR11Ecu4MR1A4gP9kEW/vCv8NmY JZ8WnAIJB4q1WVDq1DafLmL2XJrx9gbO7sK6Y1EIEPSXud1Jd16nF0P7KFG3t9/EbJ4ySa2n6IlOWlhURNJ8qgLo7G2QqvqExhRS2Ty2FgQY0tJBc8yc872jAB/ca8kOypuJHyDSP2AVzyFZ6f8snN1ixlSh50X7H54JUcd8NtUgNLSANIem6g3bDv8zc98XcONnolFIfhsPwyupOvRciXtjoYUD0ge3f6kg1of7HAlTvCj3jnswxwzVi NOd/pMwePGriMPC&key=DEJttKRPQdNRQrRRSxaS0zxfrmg3AxyLScYJ7zkJiRA SLL4gC8lpyRdwSnkEDCMGXU9gsyB3 klvpMpIOTz3rG0OJMwtqZf Jb5zvIUb2Wn/m8zHa7dFn/8H8XxBfo691cCdL2HbMzdKWXmBiXnfMNnisYnbxgD5tacwWF6RZF8ts9CP8VT SdZRX/.../Dwv3rUkqYcDTnQb8g23oQ11

http://d.baixakifiles2.com/?ic_user_id=254&data=oPVvOG3Ykdt1Pv QVf bLNKR7Jb50dVIFNbQALEFSUkAvNIz4DZDiyapocBhU3k1SJzrr1ldltCiky BUCC3PtnBnzmij5kUi7ShXYPNM2P/ iMUQEwtAhJT/rQwwBigZ3k/rHeiCEQPUf/HNcxOH0YnaeXKgstcy/rWamECmqbwkx1i/gI4UtYxDGWSsaCPM9haMJBseOQz48CqxBJkiPzh6TFI9d9oUNvtszTdFLKuoBnavpB7AOevLS8dE4SN9EBW UhgjiodgXJizMa0Be6/sULg4RgO351mvRaY9OxdpC5Ot0/gKkkygKGUNnze0m52fhF vdLQLnoTV0s07hc9a/o6tkYdeyM1t3RmnjG/Zbv6YtYYvqcxH07jsu0lEnSNVElheoyMdPwr0aagAFz72TdApGTP8xipRzOM6VI5xpMuUSPtuCkzCh8CxikqJsE0TSf99o/hsCjnjF7hGyTFHAKNMXGnZujC DzDFvVmWYtSCcZZP40TKT0hbKjOBl2bXEf4SLIyyEdkfYk8v2dc gY90Wr222x7yJNlkXHV7H6qeNldF4oJGP/LT/wMfnoTh8tSrT/pFeW4nxYSXw5A9Ce8 L6nrbQwVC1G4YpYce6NmLqRmF7bdmFlNvF/y9okWDW2IBCDnIW pwNM7Y5Ky5yE JLttHHcrqosjEBvjGlklgnaaGfDNdXppjx&key=TjUNIQMvpK7tQ9X5DjiiwFUbXImy/pRuW2/yLdAZYfpwr4z jMSP8QxMuTmXk01FFEU75XnSZXHklaEzeEtMINDducFyeF5TSxP/P d4UVb 9aLL7jBcafqo2l1HyWqvqfbN8Qq/.../KBFcRV hDDCVRswHkwb03SO2XN9muCekIyANZOFRs

Remove winrar-5-11-32-bits.exe - Powered by Reason Core Security