basketdudes_installer.exe

Bitoon Games SL

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Bitoon Games SL  (signed and verified)

MD5:
f71792946ae5013ba1be41645f9a84e4

SHA-1:
a53a762012564b91c5e6e714aa25d046bf86026d

SHA-256:
fcce77844da8e4dfeaecace875ccc006472720f24b8b687c071a0e5307e49c4e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/21/2024 6:37:22 AM UTC  (today)

File size:
115.7 MB (121,282,160 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\basketdudes_installer.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/29/2010 1:00:00 AM

Valid to:
11/30/2011 12:59:59 AM

Subject:
CN=Bitoon Games SL, OU=Security Services, O=Bitoon Games SL, STREET="Alberto Aguilera, 7 7º Dcha", L=Madrid, S=Madrid, PostalCode=28015, C=ES

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
42AE6FB0A5FDA00A96A3659AE092F36D

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3145728:V2iI2pnGKfUbO9kOFuhVtmL9eUnT5WNyzf8:w1qGKfU1OFuIReUn1WNyzf8

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file basketdudes_installer.exe has been seen being distributed by the following 16 URLs.

http://gsf-cf.softonic.com/a53/a76/.../file?SD_used=0&channel=WEB&fdh=no&id_file=328550&instance=softonic_en&type=PROGRAM&Expires=1469146103&Signature=h8Vxr8nYBPD9-lD9KZ7H~2vvLwFZWiDQ8QiCqESdEfOrvv-CrybrAUMDBfPz1Duhi-O9rKQzt6LZmunH0FP~hyAl-tmirhW-urpDCmvNY34ueR4vlLYCM8oPbRdZGn7I4niuQY9RdKPiDdvZ-bNhv8J9EYJb0Oi7cI267wEYEMI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BasketDudes_installer.exe

http://www.clearheartgift.com/YCMNLPqY_V32DZtogwH0eBz72yPi8Xvxt9FiIWTybJ2tibuLroJYm0BVFirz1WjZUsi0Q1pi6Xmo9L_mq9TI6JIcq2onPcZlL6sBUKiyls6Q7flgoHYdVRg6gOTQlwDbR04teNSdxRp2GHydOQk_RpE2E4UqbOhX_rYTjJ5jHHmUpEGMNpm0FjOOiIcLHoxanarxbd6F-G1IAAGRgu_eagscxYQMOXCIKNJOd72z7VPb3vScBvuCwrls9G42aQjul9_qpmwts_ka6buGPnrzOgsmLPS2odNyNrGZOgEZAcIqicZRiKA==

http://gsf-cf.softonic.com/a53/a76/.../file?SD_used=0&channel=WEB&fdh=no&id_file=328550&instance=softonic_es&type=PROGRAM&Expires=1475201911&Signature=SXdViZh72qOAFIZ8ga8GJCafXUgYB9lFEBhFVG0H6yj5wkzUCEmcibLTjOChzrMUZ2xAiqwKV4YTzLsJJsXeOqPbb4FNnJ80Kri6w~PpgcL9Oqrt-ETCrxlhfWiRKa6BJv1qTXUZncSULBeHmFc7mNKZ3ccoKJ3S-4fRI8Fg~0Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BasketDudes_installer.exe

http://gsf-cf.softonic.com/a53/a76/.../file?SD_used=0&channel=WEB&fdh=no&id_file=328550&instance=softonic_es&type=PROGRAM&Expires=1470630249&Signature=V9NyIYM-L~l7l1RxIpqxd1BEn8YIbomPc72cLIJALuxZxX559Ab~UVd3ZWCj1ofjrmURjdNXnqN9WJG2ba4J4o3-5y36quG5hx8pXpNqzsvHj54viK5hxkvjAlR0inqc2hKhhSm4lbV8HjnfmgZ02VQXlTbqv5rTbVhTa2MKX~g_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BasketDudes_installer.exe

http://gsf-cf.softonic.com/a53/a76/.../file?SD_used=0&channel=WEB&fdh=no&id_file=328550&instance=softonic_es&type=PROGRAM&Expires=1467009070&Signature=hfT0R1mYxrlsTIwuOPV7ScQ2q826NCu2lEEgO7hx1Gbwapcgfuoldf9PiwR0~8wPC197gR0LWOD9gwwPg5NruNc3bPH85FYNCIsJPYAR1Ts5yjh1kDrr~7PBuNnkm5iRT~1-8kT8s2H5MmWmigROrBgmfcqteoOuaJhOnKIVU-g_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=BasketDudes_installer.exe

Scan basketdudes_installer.exe - Powered by Reason Core Security