picasa-12733-dp.exe

Hof

Mode Beta (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application picasa-12733-dp.exe, “Hof Setup ” by Mode Beta (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Mode Beta (Fried Cookie Ltd)  (signed and verified)

Product:
Hof

Description:
Hof Setup

MD5:
62bc643df972428b53fa4eff0138dd75

SHA-1:
7dd85417cd89758a96a6c98e7d800197bd7c0270

SHA-256:
f5561758c93b650cd16f41c87610e371e4e0f9e6e5979dfaac059debab504b18

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/23/2024 4:38:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.6.20.7

File size:
965.6 KB (988,752 bytes)

Product version:
2.7

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\picasa-12733-dp.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 2:37:06 PM

Valid to:
7/7/2016 6:06:18 PM

Subject:
CN=Mode Beta (Fried Cookie Ltd), O=Mode Beta (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112172B4C29D53526C8AFAEF1C4F6265E881

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:LJi+t786bZa4IfLxWBrPIaPoOghcuplRS:LoM786boTqrHoj2urRS

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file picasa-12733-dp.exe has been seen being distributed by the following 38 URLs.

http://www.headbitsapps.com/WVl6OTRQVFk1YlhaMWQyNUNVM1Z6ZEV4RmNXTXdiRk00Ylc1MU9HbDBaRUZTZFVwVlEyUlZXbk5uWmtaclRVa2xNMFFtWXoxVlVGVnlWRll4TVhFeFVrVldVWEprV1VsdVJHUnFRMjFNZUcxNFJXb3pVM3A2ZVdVbE1rWjJkbHB4VlhWNVJGTlNRazloYUVwNGMzUlBVbkZ0Tm1NNGVsSWxNa0pZVFhSNU5HZHFOVEJ0VlhRemVqZDZRa1pVV1VwSFZtUkdRemxFZG1wUVEyRnZKVEpDTVcwNGIzQndiSE5yU1hOSGJUTnVNbUkxUzBoUFoweG5hemxWYkhZeE4yZ2xNa0pUTm1jM2VWa3lWME42WW1oUVdVaDNRU1V6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

http://www.headbitsapps.com/WVl6OTRQVWgzYkhCVVV6SndNR281YkRaUFdqSlVXRUZNWlZWdlRqZENORmxaVkdwRWRHcElPRWt5YjA1RmVHc2xNMFFtWXowbE1rSlFjMjVMYzBkQmMycDJTblp6UzBOUU4wODFkazh6TWpZMmNHdDVjMnR0U214RU1GY3lRV0Y0UTFOelFqQTRRM0ZEUVVjeFZpVXlRbGhVVG5Ca2NIbHhKVEpHWlRCRFlXSXpRVTh3Wm1sa04yOU1UazFvUW5WNVJVRnNiRzVIYUdZMVFXUkxabVZMVkdoT2EwWmFkRGxsVmxKQlNVSkplbmxKVUV4RWNIWnpTelYwTmpKTGJ6ZHFlVVpCSlRKR00zWnBUMWRJT0ZwWlNGcFpkeVV6UkNVelJDWmxQVEFtWm1Gc2JHSmhZMnRmZFhKc1BXaDBkSEFsTTJFbE1tWWxNbVp6ZEc5eVlXZGxMbVJ2WW5KbGNISnZaM0poYlhrdWNHd2xNbVpuY21GbWFXdGhKVEptY0dsallYTmhNemt0YzJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVVHbGpZWE5oTFRFeU56TXpMV1J3TG1WNFpRPT0=

http://www.signbodycycle.com/WVl6OTRQV1ZLT0d0UFNEaGFVV2hDWldKbU9HRlFlRXgxTlU0bE1rSm1jV0p1UTBGV1pVOW1RVlJvVEVsdFdHaENSU1V6UkNaalBXVmxjSGRsVlZWNlRETmxSMk5LU1VSamRsbHFkMU5yTWxkMmFrTnhiSGg1T1UxTldHVjJSWFE1YUUxSmJrWnRhbEpEYTBSQ2JHNXZhMjl4TUROelEyTXdNWGxUU0ZwUk9IbHFKVEpHUlVOd1JHSlRaMEUxY21vM2NIaFJPV05IZWtGTkpUSkNPRXRCWnlVeVJsWnNhelYyTlRkUVQwRTJUek5KVm5WNWRtcG5ZV3BTZFVkYVZuRk5OQ1V5Um1WSWRIQjZlVkJYYW5KSlIxWjJaME4zSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1ad2FXTmhjMkV6T1MxelpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MVFhV05oYzJFdE1USTNNek10WkhBdVpYaGw=

http://www.headbitsapps.com/WVl6OTRQVGxYVjJSaFozbFdlRWhpVFRkbVNrbG9ObkpVY0U0eWExZEhjVXg2VVRkc00xaFlTRlkzTW10NVJHTWxNMFFtWXoxbFJsTnZUMGQxWnlVeVFuZEpRemRVU1VOS2JWRnhSbXhpYzAxM2FsTTFSREZWYkVOVFdtUk9ielV3VGlVeVJrSldTbWQ1TjIweGJHSnFTeVV5UWtaUU5qUlFibU52WjI1bmNIVXlXbEJNZVRsSU5GaDBUV1JhWVRGUGNXczJXbVZQV21KalZrZE9VMEoxV1RCNVR6TkhhM2wzUzA1dmNVNUVibTVZZEdWd1dqUnlNV1ZUVlRJbE1rSm9aV2dsTWtKUmFuSkhOMk52YTBGSEpUSkNXWGhYVkhjbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpuQnBZMkZ6WVRNNUxYTmxkSFZ3TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJwWTJGellTMHhNamN6TXkxa2NDNWxlR1U9

http://www.dlsendcentral.com/WVl6OTRQWGRGWVZkRmNHZERWVlpSWW05SFdWbE1NMVJ2YUU0ME55VXlRalJQWVZrbE1rSjJORkJZYjFsSVlrSkxSM1JySlRORUptTTlVRTF3VEdGUmFWVmpVVTlaYm5CTGNEZE5ibFlsTWtKNU5GQkRlVTlEZFV0WFNVSlZkMGR2VWpjeFozaDFiRkV3WlRCNVVVWnpUMmx4VkRSaFpXd3haekJyUVV0TU9GcE1WVWRSZUZOa1oyOWlOVkl6V1hoR1dqTktSVmsxWWpaT1MySlpTV2xpU2lVeVFuZFFlazlJTms1aWJrNUtjblFsTWtKSkpUSkNTelpKYjJneFpGWnBPR05UZVdZMFpWZDFiaVV5UWxGUmFFbzNkVE01SlRKQ05GcEJKVE5FSlRORUptVTlNQ1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabk4wYjNKaFoyVXVaRzlpY21Wd2NtOW5jbUZ0ZVM1d2JDVXlabWR5WVdacGEyRWxNbVp3YVdOaGMyRXpPUzF6WlhSMWNDNWxlR1VtWkc5M2JteHZZV1JCY3oxUWFXTmhjMkV0TVRJM016TXRaSEF1WlhobA==

http://www.signbodycycle.com/WVl6OTRQVnBFUms1QlZFMXhka3RVTVVOQ1JXWkJTakYxTWxZeVdrRmhUbHBsUkZvbE1rWlJWSGxpZWs5a1NVNVhieVV6UkNaalBUQkxUbTV3ZVdsMlVsWjFkMGs1Y0ZvbE1rWlVPV1JDUjJwUE5saHdiRWRhV2tGbmFEUnVXbTFZV0hWMldUTTFhVzUxTTBWMU1rNDFNaVV5UW5oSFJ6aE1NRmN5WldsUFp6WnZObGhSVkZORU5XWnpOMUJpSlRKQ1MwOVBOV2Q1VEhsRk1YWmxjek0wWldoeWNYZEVPRmdsTWtacVMwOWxTVGxZVlRGamNWRjJhbE5vZEdzelIzaE9lalJpTTFaM01sbHhZVnBxVVdaQ1QzZHdlbGRCSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1ad2FXTmhjMkV6T1MxelpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MVFhV05oYzJFdE1USTNNek10WkhBdVpYaGw=

http://www.headbitsapps.com/WVl6OTRQVmx6T0ZBeE1sRk9NelYyVWpWNU1uYzJTbkYyV1hkMU56WmlZMGg1Y1U5Q2MwOVZTalpEUW5kaFRFRWxNMFFtWXoxb1EyRnBkblZZWkhKVmJqaE9aVTltUkVwSFdUbDFPVkZqUVZweU9Yb3pSelUxVUZablNtdHRVMU5tU3lVeVJuVnRaR1puWjJoMGJYcHFiV2xQYTNWd1JFMWpUeVV5UWlVeVFqWllabWxaWXpNNGNXaG9NakUxUlhweFQwUmxUaVV5UW1kc1VVMUlPVmRsZEhNeVVrMDBZbXgyWjBzd1JHSnNVMWRsYmtSa2NuRkxkRnBHTUNVeVJsQjFNM1E0VlZGS2NtTlRSVGRDTjFWYWFuQk5iMWwzSlRORUpUTkVKbVU5TUNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVellTVXlaaVV5Wm5OMGIzSmhaMlV1Wkc5aWNtVndjbTluY21GdGVTNXdiQ1V5Wm1keVlXWnBhMkVsTW1ad2FXTmhjMkV6T1MxelpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MVFhV05oYzJFdE1USTNNek10WkhBdVpYaGw=

http://www.headbitsapps.com/WVl6OTRQWE1sTWtJMmJUUlpWVzVsVDFOcFFYa2xNa0pwTW5KdUpUSkNhVXh1WjFNeFZERTRSMFZoVWlVeVJtUm1TSEJGVm05S2F5VXpSQ1pqUFRjeVpHeEpNbmdsTWtaRU1HTlFSa2RpVDFnNVQwNVhlVXQ1TWxkNGNHTldiRmRaUjBaaFJrVklNa3BsUVZwVlRXOUVZWFJxVVc1M2RISkJjbFpxVTBoNmRVbE9jMEZLVUhSaFZETjNhVVo0TTI1UFZrMVdSbTV1TjFSUWVIcHhZM1U1UTB4M1ZYVk5KVEpHVjBFeVdXVnVkMjlrYm5ZMlpVMUJOMUozYUZFeFUyZDNURlJaTlhWVGFYaElUVTUzVDBKVldWVldia3czYmtFbE0wUWxNMFFtWlQwd0ptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTmhKVEptSlRKbWMzUnZjbUZuWlM1a2IySnlaWEJ5YjJkeVlXMTVMbkJzSlRKbVozSmhabWxyWVNVeVpuQnBZMkZ6WVRNNUxYTmxkSFZ3TG1WNFpTWmtiM2R1Ykc5aFpFRnpQVkJwWTJGellTMHhNamN6TXkxa2NDNWxlR1U9

http://www.headbitsapps.com/WVl6OTRQVUZtVVNVeVJtTmFPQ1V5UW1sdWFuRklVR1pVUlU5V1VuSmhSRVJMVnpGMmJteHRUbG95YUZoRk9GUkdRV280SlRORUptTTlaVEI0U0NVeVFqUnJaMjV3TlZwbGFqWWxNa1lsTWtKU1NEVm1abGcwWXpNbE1rSnBiR1YwUm05Qk9YaGxkRWhFUVZFNWVtZFlWVzlpZFRGc1NUbFBUVlJ3VlNVeVJrWk5NSGh3WmtwYVRqSnJlRmRHSlRKQ1ZpVXlRbWg0VG5aS2FtaDBWV0YwY2pOd2NuQm1iRkpoUW5wM1lWbHVhMnB5ZVVWQ2VEaGpNMUo2VEZGa1ZraERKVEpHTlZSbVkySm1SRWRUUTNRMk1Va3pNVWcyWms5NWNsZG5UVWxPZHlVelJDVXpSQ1psUFRBbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0yRWxNbVlsTW1aemRHOXlZV2RsTG1SdlluSmxjSEp2WjNKaGJYa3VjR3dsTW1abmNtRm1hV3RoSlRKbWNHbGpZWE5oTXprdGMyVjBkWEF1WlhobEptUnZkMjVzYjJGa1FYTTlVR2xqWVhOaExURXlOek16TFdSd0xtVjRaUT09

Latest 30 of 38 download URLs

Remove picasa-12733-dp.exe - Powered by Reason Core Security