youtubedownloader_setup.exe

Roc

BeamMode (New Media Holdings Ltd.)

The application youtubedownloader_setup.exe, “Roc Setup ” by BeamMode (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.cycletagcurrent.com and multiple other hosts.
Publisher:
BeamMode (New Media Holdings Ltd.)  (signed and verified)

Product:
Roc

Description:
Roc Setup

Version:
1.5.4.5

MD5:
677a293f7820acd0721f529b2b15f373

SHA-1:
76be0478e0cf4421dcfa4286ac24e485e7b78c29

SHA-256:
290171cd3faa0403f4a64f46e1723e98863371ab616872170f3953f5a6401410

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
2/24/2025 11:05:19 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.4.18.9

File size:
943.1 KB (965,704 bytes)

Product version:
4.8.0

Copyright:
Internet Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\youtubedownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 7:58:18 PM

Valid to:
4/22/2016 7:25:03 PM

Subject:
CN=BeamMode (New Media Holdings Ltd.), O=BeamMode (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121179CBD5A997BA03A6A5502D9FC4DAAC6

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:HCOOQCYjs6CGC4efBPbeL7G8y9mq7qYnZOJIC3xCxcf:HHmYjrC4eJa7jyfuOOfhCC

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9316

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file youtubedownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.cycletagcurrent.com/WVl6OTRQVTVGYjNKYU1FbEdXR3c0TTFoYWVrbGpjREkyYmxkTWFVVlRWREJwYUVodVluVktSVGxGWnpKMmNVa2xNMFFtWXoxcGRDVXlRbEV6VVZjMFZYZFBSVE5YYjJwYVpUVTRlWEpWY25SdGRYbHJTVTlDT1hoVU1IUkZURlphUmxCYU1rcFFkbWQ0SlRKQ1FsQlJKVEpDWVdkTVl6RXlabEZwU1hkd1RHOVNORFZDZVVoTGVWUXllVlpoUWpWTVQwVkRUWGxFZGpCMlZFVlpUMmd4TlROeWQwTTBaak5wVVRFMVlqaHVNbVZOTTNwM1VUUk9TRzB3ZDB0cmIwUnphR3haTjNCTlkxUnZaME5xVDJoMmJYY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05V1c5MWRIVmlaVVJ2ZDI1c2IyRmtaWEpmVTJWMGRYQXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHWjJWMGVXOTFkSFZpWldSdmQyNXNiMkZrWlhJdVkyOXRKVE5HY0NVelJHUnBjbVZqZEE9PQ==

http://www.cycletagcurrent.com/WVl6OTRQVFZvYUNVeVFrTllTWEpzYUhkdlJsSllURVZyZDBSdWRuWm5WR013TTNwM1IydHJjak5ZYzNsdU5UQndkeVV6UkNaalBWZElZazFhUTJSR1ZWcEpVWFJKWjJkQlMwSnBRa1pUYmtoM1dVWnFXV2xJWnpNeE9YQmFZMVY0U0hGVWJXbGlZMlpLUkZka2RsQkdSMnB3VW5GR2FGRmljR0pKUlhOMFJrUWxNa0pEUlNVeVFsbHlWalEzUTFGRmNWUk9SVmxXV214c1NHTnNZVVZsYUZrd2Eyd3pOVUZWTkRsYVV6Z2xNa0paWWtoakpUSkdOSE0zWjJGamFqWlRNVzlrUWtOUVYycHFiVVIzWmtGalNHVWxNa0phTVhjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlXVzkxZEhWaVpVUnZkMjVzYjJGa1pYSmZVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdaMlYwZVc5MWRIVmlaV1J2ZDI1c2IyRmtaWEl1WTI5dEpUTkdjQ1V6UkdScGNtVmpkQT09

http://www.cycletagcurrent.com/c?x=EXLNfpd1kW4ixCGSsPaurLpHc0GJI 6osPdOss5WriY=&c=gJ/pET5w1OKzWQMpFAS6N0fA9v SxelVJjKYYC WMRvMRx8E6LKsX85MN634VTlenNIBfRxj9q4zQQeTtHkkzwabUqFcEPmDYvozN6P/J7sunRSPOe7lvLfOaYWgoVDZuCeNghY6y2MYuZ4zlrBq9S KhZ CwR36Xy7BdOBTXST5NTzZIlHEjinsz3Y71uLy&e=0&downloadAs=YoutubeDownloader_Setup.exe&fallback_url=http://getyoutubedownloader.com?p=direct

http://www.cycletagcurrent.com/c?x=B8FUtxt/JHZqrVB47auFoaV4At UHrWPsWlwqrmQASE=&c=1XCkj1yedHN uxBeoNtD8PeVKnXpMThClN9s6N77DksoI dkmboYNWcbTTY7H65ZhQmn4vh4c/yv96qKw0BlTRTJT4rnHcU9FBZv8HP1g3gv1HwofDJWGd6rFkN5/1ykkV gJI0Ej5JA9VR4bXvT4sKezBgXVbHtPnH/qrTaYYBO/GN4FA7i HTgbyTHiBYC&e=0&downloadAs=YoutubeDownloader_Setup.exe&fallback_url=http://getyoutubedownloader.com?p=direct

http://www.cycletagcurrent.com/c?x=X84d5ey0uZSC4GPCubwV3cjRAMqmHQkqcYuHqUdxkWI=&c=oDULRy6fIcozLkVo StbeFWkWxyteJVEchqdkhxCzkuJQ3EqKT9OI TY0Lr asGxixYC8E2TjpKKXvdIhjGuwHcnCgbw2vHNY9h9bmL7q537JmZPNgvIniQT6DjALift3GjvLOq6kstPE8hYSFnn1A==&e=0&downloadAs=YoutubeDownloader_Setup.exe&fallback_url=http://getyoutubedownloader.com?p=direct

http://www.cycletagcurrent.com/c?x=TKKmloADd6BfCAUOHH5n5CTvM0ErSZtt4QW1 jvGalE=&c=wZ5xff1IeShG BaIhV4i6CN14tWo6s8GJqm7Wb1KH7pODM7VES74lryw5lBG7/M7yOtYVH6Si7QMy87j3mqnp cTgSMYkI7qG98qXHjoFVaCs7riyWN2jT2Hcn43bcIhoFEPtlGaTZyA5OH/infm8wveWegInrmD8EDaSxAKifZd1Ax3FUR4Ua 6QkZMSA9D&e=0&downloadAs=YoutubeDownloader_Setup.exe&fallback_url=http://getyoutubedownloader.com?p=direct

http://www.cycletagcurrent.com/c?x=n1JnpcEb3VkdfVKM8uhJjmhXQm1DCxDVp7dFGLiEyxI=&c=zjAsP3EhCWvoyhIQDWMV1muvc9rF4tUE2z4nHLgcWO2mPY2I4TCNLmmKC8JpwSslKH3XdImA2p2kQoTOu3mjvQXyHP7F8Cd2EA xRok/Q/qJXqaQhVBhZwKnUNDA0Kh4dO9OKyjJyPFBoGfnpi8JyojFVLwoq/w//eC ORoKnRk=&e=0&downloadAs=YoutubeDownloader_Setup.exe&fallback_url=http://getyoutubedownloader.com?p=direct

http://www.cycletagcurrent.com/WVl6OTRQVFJVVFhSd2FtRjRUMlJTZDJGblZEUlNaa3cwZVVkd09VaHJUaVV5Um1sdVdVbDRjM0Z2Ulc5eFRIcFNVU1V6UkNaalBWbFpSMFZtWTBoQlpXVk1NVVZ1VURSb1FrZzVUVkZUTkZsSFVuazRaa2hoUlZoclNYaHJRbFZJYkZZNE5EZE1jMVp4Tm5KT1ExSkJaVEF3VTIxRlUzZHdWRFpQTUcxQmMwWnZlWGt6YTFGSVYxbzJUVzVVYTJORldUTXhhR0Z4ZWs5M2VYUlFjMjVvVkdWdWJuRlVhMkYyY0cxWEpUSkdaVFZ4ZW5CbllWTXhiSG94ZEZvbE1rWWxNa1psYVRKdlFucGljMjFCVlhSVVZEWlZaeVV6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxWmIzVjBkV0psUkc5M2JteHZZV1JsY2w5VFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtablpYUjViM1YwZFdKbFpHOTNibXh2WVdSbGNpNWpiMjBsTTBad0pUTkVaR2x5WldOMA==

Latest 30 of 83 download URLs

Remove youtubedownloader_setup.exe - Powered by Reason Core Security