five-nights-at-freddy-s-2-0-32-bits.exe

Software Installer App

Deliver.com (Fried Cookie Ltd.)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application five-nights-at-freddy-s-2-0-32-bits.exe, “Software Installer App Setup ” by Deliver.com (Fried Cookie) has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Deliver.com (Fried Cookie Ltd.)  (signed and verified)

Product:
Software Installer App

Description:
Software Installer App Setup

MD5:
b7ce753232f427d5d5068b35cb951d73

SHA-1:
abe04c1d6206071886a43e53aec1eed0398a89de

SHA-256:
73c003babcbc2d4d09b900c2f331a5f122c9cefc2b8193e8a906d5191cd863e1

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
6/23/2025 6:25:53 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/InstallCo.zkz
7.11.198.192

AVG
Generic
2016.0.3128

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15425

Comodo Security
ApplicUnwnt
20542

Dr.Web
Trojan.InstallCore.32
9.0.1.0115

ESET NOD32
Win32/InstallCore.UE (variant)
9.10947

G Data
Win32.Application.InstallCore.DI
15.4.25

K7 AntiVirus
Unwanted-Program
13.188.14496

McAfee
Artemis!8FF64F0FC93E
5600.6784

NANO AntiVirus
Riskware.Win32.InstallCore.dmfonz
0.30.0.65070

Qihoo 360 Security
Win32/Virus.Adware.8aa
1.0.0.1015

Reason Heuristics
PUP.Installer.InstallCore.Installer
15.4.25.16

Trend Micro House Call
Suspicious_GEN.F47V1215
7.2.115

VIPRE Antivirus
InstallCore
36238

File size:
732.1 KB (749,672 bytes)

Product version:
4.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\five-nights-at-freddy-s-2-0-32-bits.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/14/2014 10:12:20 AM

Valid to:
11/15/2015 10:12:20 AM

Subject:
CN=Deliver.com (Fried Cookie Ltd.), O=Deliver.com (Fried Cookie Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112157EDEEF1A59AB086421EA4B8BBEC42ED

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:7RuFahp4J/93LqU4ICjEeQD1T23xvwn79hFuBW4tLVJer31SaVxE4cz:7RuF4p4JRgIFeQD1TGeTFx4Dc5Sak4cz

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file five-nights-at-freddy-s-2-0-32-bits.exe has been seen being distributed by the following 14 URLs.

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=lKVYz0ETnRNlMKmz8zONZrPEhsriQsv043KGhRnuP6ntWVC/oMYwLtc80uw4Yf91D9uekKotQVUGvZxN3J8Ulz9BkZXR n4kv SNrSwNfK0vk/Sr6 ZrM0EHX/W4vBrPnLsrosIF9g0DzCbsaGc HVVLwEidjrISyO0c2YV0wYZ/HrKz1LfCO/IHnAyh1pmrMzLQa7TO5sMK9rzz/8mzx5N3mcU8y 25NSWP8JNExmjFsJaZGpu7IrQ1L290OG6RBBvAzD3fDbR2t6jOle30KAToyFgOhHTN5OaTc20qWGuacqV18BNP1RGBlGFDSzdx6Vh681jh9dv rCmIrmlGerlm6dwLCMAs1ZRvfR7dYwrM6ZPQF9lbgvLeDbC3mL7lEQtoFikYmFZkaUdO34/33CqCSvVLCGHDggDRFjve3Y0mbA8dd4pL68AbKXu/iSWYKm3wCXO3D/jjW/zlg5kP/nNjHpm9y10aMo5grRyvl5M5/lWDSnh9xMpiwkyt0mPhpEwt63woZ/bAebCwOIYbXqa4eZqDEhXGJGlEYNXtY/.../LND7Ips3RRf7lNQxoY v8Q1zWxCN1AMc8A38UbTLyW3FpSevCXYUR8h6xtrKHCDtL7Kk 1Stu5pU2vCOM FLrbbzjNTI9OamXHfEXS6DZ9Ua2w XJumsQnlV9MahsapgqqbefCr070iBn0KsaWHhJLnzw4TBLzmmHpp0FbDSGols9W5pIjXMYbiUkUkAKdSBsiltt1hMfO JsBuGzaXcxn cRgSeEw4S6bOHbFqiu2Cbn2HT0onawCiH kndJvxexuzystl4260Bn2U0qyHAU=&key=jJeI8K6Vl042lV3TIOi4QaJkD0vJs6jLptrzxs8YTytmBRI1s

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=Apu9FiiQh1M9Y9sJbzmlC0w5vgZBYArS6eOGNxrSsxNHcbpb9pldc4f/FNiqGeEzJuu5JYYGNA qAOkFmACTJk3RPjpP17FtSDuQh65lB9olRjBEHkiIl1z2/xg0EsjKjAoXj9XadlBAws7L5Z5ZzdBAA CBd4 7J mBnEUFaFXSM4V1/bdun7GmMtM4 ZMJ2TbiARwZpwIT/JEpEqK/Cxe1DYvk9im6qo0QhVs/qf94t LVp0/d5Igdx9kOyJjsFSb92YtvP5M mriuM8H7PoZCKjrf2d8EyzvFNFcqocJAygfrnGIGXFlX2JSimXgJoK RMQbrVrcj2QSzUugqX6Q261YCCEM8TfBX2L3iFGeEzaP/TqQ9ud6Bt9EyGOC1wzwO8DXXAftey//IQBT Au1M5w8lHF5woF6JRAZELDC4i7eY4sdaMy1dxseXPVh91ND6vFFZgGLpHp5 251Z1B3FXyhk4u3Bf9cDvYL6S1LVaAb2qp3Dg50BsHYGO2ks1XSGhVjAAzRuqcxXU6cDH2yAs8kZoG81f2hOPg67mElC/1o TDdcZldbvlzN3Yk9m4S/MkCfaBJp1wxjpbXILCDz1ykyv7Gab7shwgSc6ePTcVhcS bp8IPogkfHqeE3MfCjYg7VI2nTEOVXAM66 fZ/TFHh5dqxElEciuoz8wkKy2xofTGLnOqPHeKP7uI 2rSdAHr1nLUU852YUwgaWhvgz4ijCSxI6dU oylqO7dRUjC6zlDM0vBeTmQSb6 MytUBS7aCuiLXjy7PzbaHWFpfNtW7bRb2zlsTUfD48hw05iitH0pjmaRm4wMuN2A/V64Il BWXZvB8OpbnieGpGk8LLq71LNmuetxq/.../W7Ybk1oNis

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=7yCm0ArW1iNCY8OA5ZI6v5mddWVC3UyA8P/gPS4QfjoGlWX ccPX3z5c3OErpQ55MNNaIatwvWdanGNr6q/WJax/DexWYb7D0rTZw2Qorv1k0KaEnEGGbKSVxL10koPuEoqGjE7Yog7So9F4nNpMwOr1IzGy5uYgPoMMgcoNSkyZw0jP OZXSe0vApVF1Kuu4iWaTDx QaFUHWCemW51d2SU/2LIUpJnUJeDUU4Boogj2k7G1OQvvdszfVMR9RKzy7oEQsbzl/dxbAlzUNsD4hdM1r8snmH5x/NokSLOMCg/m23E7ZW35amsFj95DcZ03Ri6re7/veD3GQvsB jlCgFQWrnMw1TttAhiFZmOJ7ya6pMPLiMLm9irXjqZ3ou3VampAESszU6kY3Sf x0tE Viwjab8Rw4C2Kk0nToYvnUQuAPvEomJOrxhPAQoZrrfVVN0M3xPggrZ/UrdB7FxDCopFEwaHBjb0IcGT6Jrz12afMZRq/Ft/gN 8o/ma eY24gVlGMvTxCk1jf7nBoNP2rypnYiTrK6mWR6/3qXE9ZaEkfIrXsGW1o8Hrb3ZjKGSjKWUpwOcV8YJpKdfNByYJ5sGxME3rOvRqwhpewKgbdQjClmLTP9YkdFpAzzKuEEM6N5aFHzc7lqpWiUe6rKqlc68bQJw9mrHxDRro9cixvxwHw1JjjZvjDHMr/TqseHKw0DANi5huR/ZNeuXyxbcE MSTfKReKEIkgDn1e2Oz ck56iLyzV3VI7crPeN5axrRyET/FW25cRBwT6a/lJH82chhtuoff oDkc5yvtVVE CZVywfPoGOnkKGBF/.../BgIM2pC2jpezr4UQ

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=jbfSzHpdlzed4MLmtEr7U5xSf8kj/mCGv4XzM7pS/mhBHq2QnyK6Z2Y2AT4us8lXOca6UKBvZRdKAFwX5K4uZxj9TxM9sH tGuafb49jRgPYNLAC0TNb1E2H05cGhypmmeNmgu49MA6pPN7836KmGEQJwX8nZpRtDKj2IevsQUNuKPtrna5zcxWhvFkw9GZtGZkQ2SPd2zjwVTJR2 M97okrNMtGsqV0gfTQ6MU0ScWG8lVLBG/izY70w0nVjE6VXeIuTYKp8 cb4alHpSOPyNS5MTmA zsU5Q aEeSdkBIADCTV4BWuPvXVCEUo8usfeKiDnd/Rw2q2v1T7t9T1coyCbfK4c5Dlx4lu9hQm0YIk0QE4DDNObEdOxxJVHrdlIKcNYsVuxiGmhXZZcH3BwYAQTvyRI5sYl/L5JMwSA5otBtw4nWoYLzMgS4XQ9Ky73T/MbgVCu/KFlXEeymZ1Fg8BEIEctALQN4dcRgi3f/dehVZiu43mVrEXYOVqRPmyntY aNXVLVM/HATiDIpeFWwmIt5S7tosoDU/x2X23 8zxRJkLJx51D7RnmfIJTu185t8PRvfDNh7kV6r4w9eHEfZLkKMsOg8JvwtvpMX3rdllv8dnLPFFbHD1V6NFayXM3qaj/JPLv4GnqDEpXAldo2OZPNx l8EnrnMZ3k17mVGOaE GX2WNw/lv4tkiakXrMXSRGbGd89DBRmNOa7tVSlmasyq Rdm9x7L5mKbkBHUL9phKBlluaVvfIxTV/nlnmcxXz4nryf8dpExboKeEO2e6uJfrnvTvvAJ0cOuu7QYA5/osBbE8q0JoCey1XZVgH2XnueYjTiFEE2iQV2y8sHe7r/.../3JpeUNpWhKFo4U

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=ScH6cvkXx7Fl9I8gO0dXFmg9yxPFVTTVs4qJyVidxVKvB90QUYtak/VcZFIXLwReck97U4lEV6kFtMO/DePMwoPqazv/Xkvc0j7b bRERQIYDBpn3gQYkTNEdTWsIJA6fVCFwU52wUr3wJ8k8wuWbcnpuXzqTxjIfvjzsns xAIRt7/VoyxpqD5wJSxf9qYEKEB3WoBzkvZJj3yaTJ8L2LwEN0T758ciy3svKfgfDdPet6aFr1plNzbARE qy0K8Kli8aiuMnMAQI3QLUTGMrnCyHXbBdJgW/z7pJh5Bq8U69 VR6lu0SmRLUNLbAJ BKw2TSKjDc36NWuJrrPLpM1V AXuRwS6d28S15W2dMDMVkw0jH/iIfqDypZ2ptEjvsVsdTOxhk62tn9Rq47IA0kmOzDI9gX kDJhFASGLnMbxaLw FViZjrERrcgvZNLjyB6IGfWCUcW9p0N6oVjcuhtoQd0cMU4 hpTweFrU/DeM54FzsuifRT bujqPT1n2Skk5I/xyyz6MHYgoIHncidc8gpcfi VYXe4XJtxNEOdULn0l6aV 5az2yOa LX7mIAzQS8uGmhoRyEmX23TbVp7/6xzA8NAY0m6xZHJ0UhvxomOWgfkzqhe66dmtLD20aY364g511ca0GF CLrt5BAk6AABHgRfPACKzWqkKfszxbqo KJFvrrzIvnqElhx6wSIgXcceUOef9efN7uMW3/.../tSGQUiwRqKa6KUuGvTUwIKZGK801gESzelQjicw6f

http://cdn.clickjogoscontent.com/?ic_user_id=495&data=HXWKUJMvndbhJIngVQ4umvFmgegGz1kB/UupjUNc7mDjA2JaTVtjNvzgcN0PODavjVk963hkjaYBN0f825lD5ntMdcxXEAhl3r RZaaxxGXdtzHgYwh92iuotc7mTTL2be/njAcFJ/CL66qdRPpY1m8AAUyqO1d7l0slv/NEmsLHPIN4nUeYtWVA9Qlm158ng/S oa1ZIiFZvmDDspx64yGf3LdsW35el5l7j6jSudOm6RzZun88q3 1bjO/XTxAepgrZyjSjVlEQbGy6nSidWfo2XCjuSz/aMN1DfhNdsoefwicczapTqj3visNNkcFl9 VWDz4v3ZB8FU uQytDLantH1njLi6Y7qg3u2AuIXrowYBB0H1VzClxHCM9xbmYYY/kQFefIbpzlEZjckomsTQCXKj5jw2ZrIt7Pp6FzFhBKuyvvmo5CAb7xm5FDSq1K4FEkCBLE1tOO9fxJZXQsE0ZDMLDorUlk0MjUYOx3OdzmyNwmuEIjLaSeVH2/zmiIxpfU67tcEG9DTkjxn7e62tMpmEjrQLO1uM Tl6Aqx ax9Q7kK0s9TnnXpWwf/VJ1b0KOhuJi7wjF0GAjqoOSJ2QqjiLwi1kWrk99T6FORkh35YTkqWslLkCWbsUjUKZ0gRkUMMN93HeZz SUMUp7y 1n7w/XbpBcefogojg7hmbllRbmYWzu xJgqZFDLLlK6djxWhdEFJLgC7nEgIkChOLL5 bMybWz82AB5HjIvSTZcG8ksZgZnewiBVcv9gAmkk2s1IZ NZMaTgYL5OPwbQsUTDYQZFsN1uZ7EShF8ZBwVZ0gie512kKCGPU3l1EhVt 9eBcglzg5eNMF7FiBkUy6LvnEaMNyyg278KQO49kzb9ET3xz4TjZk=&key=XJuH9OvfVVui7N/.../vZUVIUorssJzoL

Remove five-nights-at-freddy-s-2-0-32-bits.exe - Powered by Reason Core Security